This page summarises how PromptSafe handles your data, for procurement, security, and governance reviewers assessing us as a supplier. It is written in plain English and is deliberately short.
It is a summary, not the contract. The Privacy policy is the authoritative document on data protection, and the Terms govern use of the platform. Where this page and those documents differ, those documents apply.
1. Where your data is stored
- Customer workspace data is primarily stored within the European Economic Area, on infrastructure located in Frankfurt, Germany.
- The database and authentication layer run on Supabase. The web application and this marketing site are delivered through Vercel.
- Some service providers process limited personal data outside the UK or EEA, including in the United States. See section 5 below.
2. Encryption
- All traffic between your browser and PromptSafe is encrypted in transit using HTTPS (TLS). This applies to both the marketing site and the platform.
- Stored data is held on managed cloud infrastructure from the providers named above. If you need our encryption-at-rest configuration documented for a supplier assessment, ask and we will provide it.
3. Workspace separation and our access
- Workspace content, meaning your agents, personas, evaluators, and conversation transcripts, is logically segregated from other customer environments and is not intentionally shared across workspaces.
- We do not routinely access customer workspace content. Limited access may occur where reasonably necessary for support, platform maintenance, security investigation, legal compliance, or prevention of misuse. Access is restricted to authorised personnel and limited to what is necessary for those purposes.
- On enterprise engagements, our team may work inside your workspace as part of the agreed engagement. That access is documented in the order form or statement of work.
- We do not use your workspace content to train third-party or general-purpose foundation AI models. The distinction between the material we do and do not use for research and product improvement is set out in the Privacy policy.
4. Access and authentication
- Accounts use email and password authentication. We do not currently offer social sign-in.
- Multi-factor authentication is not available today. If it is a requirement for your organisation, tell us, because it helps us prioritise it.
- Access to workspace content is scoped by role within a workspace, and enforced in the database itself through row-level security rather than only in the application.
- You can ask us to remove an account by contacting info@sacher.ai.
5. AI model providers
PromptSafe runs simulated conversations through third-party large language model providers. This is core to how the product works, so reviewers should account for it explicitly.
- When you use PromptSafe with model access we provide, conversation data is transmitted to those providers for processing. That includes your agent's instructions, synthetic persona messages, agent responses, and anything you type during a conversation.
- The providers we integrate with are OpenAI, Anthropic, and xAI. They process data in the United States.
- Transfers outside the UK or EEA rely on recognised safeguards, including Standard Contractual Clauses, the UK International Data Transfer Agreement, and the UK Addendum.
- On the enterprise tier you can connect your own provider API key, in which case your use of that provider is governed by your own agreement with them.
6. Subprocessors and change notice
The full list of service providers, what each one does, and whether it acts as a processor or an independent controller, is maintained in the Privacy policy.
- We give customers advance notice of any intended addition or change to our subprocessors, so there is an opportunity to review the change.
- Notice is given by email or through a notice on the platform.
7. Retention and deletion
- Workspace content is retained while the account remains active, and is not retained indefinitely once an account is closed.
- If you need specific retention and backup periods documented for a supplier assessment, ask and we will confirm them in writing.
- You can request deletion of workspace content by contacting info@sacher.ai.
- We may retain limited backup, billing, audit, security, fraud prevention, or legal compliance records where reasonably necessary. Full detail is in the Privacy policy.
8. What you should and should not put into PromptSafe
PromptSafe is a pre-deployment testing environment. It is designed to be driven by synthetic personas, not by real people's data, and that materially reduces the risk profile of using it.
What we mean by synthetic
Synthetic means generated, not derived. The personas and conversations PromptSafe creates are artificial from the start. There is no real person behind them.
A real conversation does not become synthetic by having names and identifiers removed. Anonymised, pseudonymised or de-identified transcripts of real people are not synthetic test data, and under UK data protection law they may still be personal data. If the material started as a real conversation, treat it as real, and talk to us before sending it.
- Personas and conversations generated by PromptSafe are synthetic. They are not real patients, users, or service users.
- Please keep identifiable patient information, and other special category personal data such as clinical records, out of the standard platform. It is built for synthetic test data.
- If you need real conversations evaluated, for example inside a research study, contact us before sending anything. We set that up under a separate agreement with the appropriate data processing terms, rather than through standard platform use. That applies whatever lawful basis and safeguards you hold, because it is how we run the work, and it is described on our research page.
- The Privacy policy and Terms govern the legal position.
- The platform is intended for business and professional use and is not directed to anyone under 18.
9. Certifications
We do not currently hold SOC 2 or ISO 27001 certification, and we do not claim equivalence to them. We would rather state that plainly than leave a reviewer guessing.
Capital Consult Ltd is registered with the UK Information Commissioner's Office (registration ZC144061). Registration is a statutory requirement rather than a mark of compliance. We process personal data in accordance with applicable data protection law, including the UK GDPR and the Data Protection Act 2018.
10. Reporting a security issue
- If you believe you have found a vulnerability, email info@sacher.ai with enough detail for us to reproduce it. Please do not test against other customers' workspaces or attempt to access data that is not yours.
- If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities in line with our legal obligations.
- No system is perfectly secure. We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access.
11. Questions from a procurement review
If you are completing a supplier assessment and need something this page does not cover, including a data processing agreement, email info@sacher.ai and we will respond directly.