This page summarises how PromptSafe handles your data, for procurement, security, and governance reviewers assessing us as a supplier. It is written in plain English and is deliberately short.
It is a summary, not the contract. The Privacy policy is the authoritative document on data protection, and the Terms govern use of the platform. Where this page and those documents differ, those documents apply.
1. Where your data is hosted
- Customer workspace data is primarily hosted within the European Economic Area, on infrastructure located in Frankfurt, Germany.
- The database and authentication layer run on Supabase. The web application and marketing site run on Vercel.
- Some service providers process limited personal data outside the UK or EEA, including in the United States. See section 4 below.
2. Encryption
- All traffic between your browser and PromptSafe is encrypted in transit using HTTPS (TLS). This applies to both the marketing site and the platform.
- Stored data is held on managed cloud infrastructure from the providers named above, which encrypt data at rest as part of their standard platform.
3. Workspace separation and our access
- Workspace content, meaning your agents, personas, evaluators, and conversation transcripts, is logically segregated from other customer environments and is not intentionally shared across workspaces.
- We do not routinely access customer workspace content. Limited access may occur where reasonably necessary for support, platform maintenance, security investigation, legal compliance, or prevention of misuse, and where possible with your authorisation.
- On enterprise engagements, our team may work inside your workspace as part of the agreed engagement. That access is documented in the order form or statement of work.
- We do not use your workspace content to train third-party or general-purpose foundation AI models. The distinction between the material we do and do not use for research and product improvement is set out in the Privacy policy.
4. AI model providers
PromptSafe runs simulated conversations through third-party large language model providers. This is core to how the product works, so reviewers should account for it explicitly.
- When you use PromptSafe with model access we provide, conversation data is transmitted to those providers for processing. That includes your agent's instructions, synthetic persona messages, agent responses, and anything you type during a conversation.
- The providers we integrate with are OpenAI, Anthropic, and xAI. They process data in the United States.
- Transfers outside the UK or EEA rely on recognised safeguards, including Standard Contractual Clauses, the UK International Data Transfer Agreement, and the UK Addendum.
- On the enterprise tier you can connect your own provider API key, in which case your use of that provider is governed by your own agreement with them.
5. Subprocessors and change notice
The full list of service providers, what each one does, and whether it acts as a processor or an independent controller, is maintained in the Privacy policy.
- We give customers advance notice of any intended addition or change to our subprocessors, so there is an opportunity to review the change.
- Notice is given by email or through a notice on the platform.
6. Retention and deletion
- Workspace content is retained while the account remains active.
- You can request deletion of workspace content by contacting info@sacher.ai.
- We may retain limited backup, billing, audit, security, fraud prevention, or legal compliance records where reasonably necessary. Full detail is in the Privacy policy.
7. What you should and should not put into PromptSafe
PromptSafe is a pre-deployment testing environment. It is designed to be driven by synthetic personas, not by real people's data, and that materially reduces the risk profile of using it.
- Personas and conversations generated by PromptSafe are synthetic. They are not real patients, users, or service users.
- You should not input real personal data of identifiable individuals without an appropriate legal basis, and you should not upload special category data such as real clinical records.
- The platform is intended for business and professional use and is not directed to anyone under 18.
8. Certifications
We do not currently hold SOC 2 or ISO 27001 certification, and we do not claim equivalence to them. We would rather state that plainly than leave a reviewer guessing.
Capital Consult Ltd is registered with the UK Information Commissioner's Office (registration ZC144061) and processes personal data under the UK GDPR and the Data Protection Act 2018.
9. Reporting a security issue
- If you believe you have found a vulnerability, email info@sacher.ai with enough detail for us to reproduce it. Please do not test against other customers' workspaces or attempt to access data that is not yours.
- If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities in line with our legal obligations.
- No system is perfectly secure. We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access.
10. Questions from a procurement review
If you are completing a supplier assessment and need something this page does not cover, including a data processing agreement, email info@sacher.ai and we will respond directly.