Security, confidentiality and privacy

Everything about how we protect your information and your clients'. Unlike generic AI services, your information never leaves your control.

Last updated: January 2026 | Document version: 1.0

Key security points

Your data is yours

Every document, conversation and analysis stays in your infrastructure.

No AI training

Your information is never used to train artificial intelligence models.

Isolation per case

Each case has its own isolated knowledge base. No mixing of information.

Full encryption

Encryption in transit (TLS 1.3) and at rest (AES-256) for all information.

Comparison with public AI services

Understand the difference between using ChatGPT or Claude.ai directly and Iurefficient

FeatureChatGPT / Claude.aiIurefficient
Data locationThird-party servers (USA)Your private infrastructure
Training on your dataPossible (depends on settings)Never, processing only
Knowledge baseGeneral public knowledgeOnly your documents (local RAG)
Data isolationShared among usersIsolated per case and client
Conversation retentionPer provider policyFully under your control
Audit and traceabilityLimitedComplete, with detailed logs

Privacy and artificial intelligence

When you use ChatGPT or Claude.ai directly, your conversations are sent to third-party servers and may be used to improve their models. Iurefficient works differently: your information is processed locally, and only processed queries are sent to the AI APIs, never full documents or sensitive data.

🚫

No external training

Your documents and conversations are NEVER used to train third-party AI models such as OpenAI, Google or Anthropic.

🔐

Isolated processing

Each AI query is processed in an isolated environment. Data is removed from memory immediately afterwards.

📍

Private servers

All infrastructure runs on dedicated private servers, in line with applicable data protection regulations.

🗑️

No retention

We do not store the content of your AI queries beyond the time needed to process them and show you the answer.

Technical infrastructure

Deployment options

🏠

On-premise

Installed on your own servers. Maximum control and compliance with internal security policies.

☁️

Private cloud

Deployed in your AWS, Azure or GCP account. Cloud benefits with full control.

🌍

Managed cloud

We run the infrastructure with guaranteed security and availability SLAs.

Legal compliance

🔐SSL/TLS 1.2/1.3
🛡️Enterprise controls
🌐GDPR ready
☁️Based on ISO 27001
🏛️Professional secrecy

Frequently asked questions

Can the AI make up information about my cases?

The system is designed to minimize that risk. The AI answers only from the documents in your case, not from general knowledge. Every answer includes verifiable citations and a confidence indicator, and if there is not enough information the system says so clearly.

Are my documents sent to external servers?

No. Your full documents never leave your infrastructure. Only small, decontextualized fragments are sent to the AI APIs when you ask a question. Those fragments contain no client identifiers or information that could link them to a specific case.

Can OpenAI or Anthropic see my data?

The enterprise APIs of these providers have strict no-retention and no-training policies. Data sent through the API is processed in real time and discarded immediately. It is neither stored nor used to improve their models, and this is guaranteed by contract.

Can I use Iurefficient for classified information?

For highly sensitive or classified information we recommend an on-premise deployment with local AI models (no connection to external APIs). This configuration is available for organizations with special security requirements.

What happens if there is a security breach?

We have an incident response protocol that includes automatic anomaly detection, immediate notification to those affected (within 72 hours, as GDPR requires), forensic analysis, remediation of vulnerabilities, and reporting to the authorities when required by law.

How can I verify that my data is safe?

You can review the audit logs at any time to see who accessed which information. We also offer independent security audits and compliance reports on request.

Are my files encrypted on the server?

Yes. Since version 4.5.0 every uploaded file is automatically encrypted with AES-256-GCM, the most secure encryption standard available. Highlights:

  • Transparent encryption: files are encrypted on upload and decrypted on download automatically
  • Per-case keys: each case uses a unique derived key (HKDF)
  • GCM authentication: detects any tampering with the file
  • Backward compatible: earlier files keep working normally

Even with physical access to the server, files would be completely unreadable without the master encryption key.

Your information is safe with us

Try Iurefficient knowing your data is protected

Start free trial