Platform Security & Governance
Security Architecture
Every agent on DevBuildTool Agents operates under a shared, strict security contract: zero persistent document retention, evidence validation, and isolated credential boundaries.
1. Ephemeral Document Processing
Whether validating insurance certificates, extracting engineering requirements, or auditing operational documents, source files are never written to permanent databases.
Held in Memory for One Request, Then Purged In place
Uploaded document bytes reside only in the volatile server RAM of the synchronous request worker. Once text extraction and rule evaluation complete and the response payload is returned to your client, document references and extracted page text are dropped from memory in an explicit garbage-collection step.
No Database File Persistence In place
We store only authenticated credit ledger balances, payment confirmation hashes, and user-confirmed rule sets in our persistent storage. Uploaded PDFs, raw images, and completed report files are never stored in databases.
2. Cloudflare Edge Gateway & Turnstile Protection
All ingress traffic is screened globally at Cloudflare's edge before reaching application compute nodes.
- Bot & DDoS Mitigation: Cloudflare Turnstile validates human interaction without invasive CAPTCHA challenges.
- Rate Limiting & Abuse Prevention: Global request rate limits are enforced via distributed Cloudflare KV stores to protect model quotas and prevent service denial.
- End-to-End Encryption: All communications between browser clients, the Cloudflare Worker gateway, and the Python backend run exclusively over authenticated TLS 1.3 connections.
3. Bring Your Own Key (BYOK) Ephemeral Isolation
When using BYOK mode to supply your own Google Gemini API key:
- No Client-Side Storage: Your key is held only in an ephemeral JavaScript closure variable while building the multipart request. It is never written to persistent browser storage or client caches.
- Never Transmitted in URLs or Body: The key travels exclusively in a single HTTP request header (`x-gemini-api-key`).
- Immediate Server Discard: The server reads the key from the header for that single model invocation and blanks the reference immediately upon request completion.
4. Third-Party AI Model Provider Data Terms
Specialist agents use Google Gemini foundational models strictly for multimodal OCR and fact extraction:
Google Gemini Developer API (Google Gemini Developer API)
When operating on the developer API, Google retains prompts and contextual outputs for up to 55 days for abuse monitoring (verified on 12 August 2026). Data submitted via our enterprise API pipeline is not used to train or refine Google's machine learning models.
Google Vertex AI Enterprise Mode (Google Vertex AI)
For enterprise deployments configured on Vertex AI, data is governed by Google Cloud Enterprise terms: zero retention for abuse monitoring, zero training on customer data, and data residency locked to customer-selected cloud regions.
5. Audited Telemetry & Data Redaction
Operational telemetry is strictly segregated between request metadata and sensitive payload data.
What We Log
- Request identifier
- Whether the platform key or your own key was used
- Which model API served the check
- Number of documents and total page count
- Model name and number of model calls
- Whether a document had to be read again by a larger model, and why, as a code
- Latency and token counts
- Counts of passed, failed, and review results
- An error code, when something failed
What We NEVER Log
- Document contents, in whole or in part
- Extracted customer names, policy numbers, limits, or dates
- Request or response bodies
- Anything shaped like an API key or bearer credential
Security Questions or Vulnerability Reports?
Our security team takes all responsible disclosures seriously. If you have discovered a security issue or require an enterprise security questionnaire, please contact our security team at support@devbuildtool.com.