Security and data
Retention, exclusions, encryption, tenant isolation, AI data use, support access, export and workspace deletion.
Your paper is built from some of your company’s most sensitive systems. This page explains what we store, for how long, and the controls you have. Controls live at Settings›Security & data (admins and owners). For our policies and subprocessors, see Security and Subprocessors.
What we store
| Data | What | Kept |
|---|---|---|
| Raw evidence | Items read from sources for an edition: titles, excerpts, transcript turns, structured fields | Your retention period |
| Facts | Short extracted claims and verified quotes, cached per item | Your retention period |
| Editions | The published paper, its quality report and approvals | Life of the workspace (it’s your archive) |
| Source credentials | OAuth tokens (held by our integration partner Nango), API keys and MCP tokens (encrypted by us) | Until you disconnect |
| Reader analytics | Pseudonymous, per-workspace hashes, never names or emails | Life of the workspace |
| Slack excerpts | Up to 600 characters per message | 30 days at most, whatever your retention setting |
Retention
Choose how long raw evidence is kept: 7 to 365 days (default 30). The data map on the security page lists each source and its retention. Published editions are kept as your archive until you delete them or the workspace.
Exclusions
Keep people, channels and topics out of the paper with exclusion rules and the never-mention list. Both are applied in code before any model sees the data. See House style. Email addresses and phone numbers are redacted from evidence automatically.
Encryption and isolation
- TLS everywhere in transit; storage encrypted at rest by our database and object-storage providers.
- API keys, MCP tokens, webhook signing secrets and model-provider keys are additionally encrypted with AES-256-GCM before they are written to the database, and decrypted only when used. They are never logged and never shown in full again.
- Every customer table carries your workspace id, and every query is scoped to your workspace on the server. Stored files live under a per-workspace prefix and are served only to members or through signed links.
- Editions are never public: the web reader requires sign-in as a member, and every page is marked noindex.
- Every sensitive action, such as revealing a secret, exporting or changing roles, is written to an audit log.
AI and your data
- No training. We use model providers under API terms that prohibit training on your data. We never train models on your data either.
- Minimum necessary. Models see only the reporting window’s evidence, after exclusions and redaction, and only for the stage that needs it.
- Read-only. Models have no tools that write anywhere. Source content is treated as data, never instructions.
- Zero data retention. Workspaces can be restricted to providers offering zero data retention. Contact support to turn this on.
- Your model, your key (Business). Choose the model per stage or bring your own provider key. Enterprise can point at a private or open-source model endpoint.
Support access
Paperbeam staff can’t see your editions by default. To let support look at a problem, switch on Support access. It grants 72 hours, then expires on its own. Even with access, staff must record a reason, and every view is audited.
Export
Export archive (JSON) downloads every publication, edition setting and issue, including full content, as one JSON file. Admins and owners only; each export is audited.
Deleting your workspace
Owners can delete the workspace at the bottom of the security page by typing its name. Editions stop immediately, and there is a 7-day grace period in which you can Cancel deletion. After that, workspace data is permanently deleted. Cancel your subscription in the billing portal as well, so you aren’t charged again. For a data-subject request about one person, email privacy@paperbeam.ai.