PrecisionDocs

Security

How PrecisionDocs protects project data, documents, account access, and AI workflows for professional land development teams.

Three things you should be able to answer about any AI tool.

Where does my data live, how is it protected, and what can I control. Here are ours.

What we store

PrecisionDocs stores the data needed to run the product: account profiles, organization membership, project and parcel details, chat history, uploaded documents, generated reports, private search indexes, usage and billing metadata, and operational logs.

How it is protected

TLS in transit. Provider-managed encryption at rest. Per-project isolation enforced at the database layer through row-level security. Private storage buckets, signed download links, server-side rate limiting, CORS allowlists, SSRF protections, webhook signature verification, and browser security headers.

What you control

You control who joins each workspace and project, what documents you upload, whether organization data sharing is enabled, and when live project data is deleted. Data sharing is off by default for new organizations unless an authorized user expressly enables it.

Public sources first. Private uploads when they help.

Many feasibility questions can start from public sources: federal data, county GIS, municipal codes, and parcel records. When you upload private documents, PrecisionDocs stores, parses, indexes, and processes them so the agent can answer questions and generate reports. Uploads are optional for many workflows, but they are not ephemeral once provided.

  • Ask any parcel question by address.
  • Pull federal flood, soil, elevation, and wetlands data.
  • Look up zoning across thousands of indexed US municipalities and counties.
  • Generate a complete Site Investigation Report.

Operational data has a lifecycle.

Active project content stays available so the agent can search documents, preserve chat continuity, generate reports, and maintain project context. Deleted project data is removed from live project storage, uploads, chat, memory, and project search indexes. If organization data sharing is enabled, newly shared documents may also be copied to a separate internal model-improvement archive.

First 30 days: Active

Hot path. Full document text and embeddings stay searchable for the agent at low latency.

30 to 90 days: Warm

Older chat is summarized to keep agent context efficient. Documents stay searchable.

90 days and beyond: Cold (active organizations)

For active organizations, document vectors are evicted to reduce storage. They re-embed on demand if you return to the project.

Warn at 90 · delete at 120 days: Active organization delete

For active organizations, owners are warned after 90 days without project activity and permanent deletion is scheduled no earlier than 120 days without activity.

Warn at 30 · delete at 60 days: Inactive organization delete

For inactive organizations, including expired pilots or services, owners are warned after 30 days without project activity and permanent deletion is scheduled no earlier than 60 days without activity.

Account controls that match how engineering teams actually work.

Per-project ownership, per-project deletion, per-project audit trail. No shared dumping ground.

Who sees a project

Owner-only invitations with explicit, expiring tokens. Maximum four members per project. Membership shows in the chat panel so everyone knows who is in the room.

When data goes away

Clear chat and delete project both require typed confirmation. Delete cascades through uploads, agent memory, chat, and indexed search.

What the agent saw

Every claim the agent makes carries a citation chain you can audit. Export the full audit trail as a structured spreadsheet for your project file.

What you choose to share

You can run a complete site evaluation without uploading a single private document. Uploads are opt-in and scoped to each project.

What we use, and what we never do.

Honest disclosure. The platform isn't passive: we collect and use some signals to make it better. Here is the full list, and here is the line we will not cross.

What we use, and why

Operational project storage

We store project details, parcel context, chat messages, uploaded documents, generated reports, project memory, and private search indexes. The agent must read project content to answer questions.

Third-party AI processing

OpenAI and Anthropic process selected prompts, project context, and retrieved excerpts to generate answers and reports. Third-party AI providers do not train their models on your API content unless a separate provider opt-in is enabled; PrecisionDocs does not enable provider training for customer API content.

Internal model-improvement archive

If organization data sharing is enabled, PrecisionDocs may retain direct-upload documents and related metadata in a private, access-controlled internal archive to improve our own models and evaluation workflows. When disabled, newly shared documents are not added to the internal model-improvement archive.

Anonymous product analytics and operational logs

We use aggregated website analytics, feature-usage signals, status codes, latencies, request IDs, and limited error metadata to run and improve the product. Request and response bodies are not logged by the request logging middleware.

Cited public sources

The agent reads government data, ordinances, parcel records, and other public sources to answer your questions. Those sources are public and unchanged by your use.

What we never do

  • Sell your data, prompts, uploads, or reports to anyone.
  • Let third-party AI providers train their models on your API content.
  • Add newly shared documents to the internal model-improvement archive when organization data sharing is disabled.
  • Expose one customer project to another customer.
  • Use your project content for advertising profiles or remarketing.

Related reading