Scaffold · Data & security

Where your product data lives, and where it goes.

The short version: your workbook is stored in the EU, and the AI that drafts with you runs through providers in the US. Here is the longer version, including the parts that are not the simplest to say.

Stored in the EU

Your workbook, the documents you upload and every backup sit on Produxity's own servers with Hetzner, in the EU. Documents you upload are read on those same servers, not handed to an outside service.

How: the database, the job queue and document extraction run in one EU deployment. The nightly backup goes to Hetzner Object Storage in Helsinki and covers the database. It does not cover the files you upload: those sit in the server's whole-machine backups, which restore a server, not a single file. Keep your own copy of anything you upload.

Processed by AI providers in the US

To draft an answer, Scaffold sends the relevant part of your workbook to a model from Anthropic, OpenAI or Google, all three US companies. Council activities send it to all three at once, so that each can check the others.

Two other US services see some of your material: Exa runs web research, and OpenAI builds the search index across your workbook.

Google runs on its paid tier, which is not used to train models. We are not making that promise for every provider yet: Exa may keep the search queries we send it until a zero-retention agreement is signed, so we say so rather than claim otherwise.

How: every generation goes through one code path, which also switches off OpenAI's option to store what we send.

Who handles what

WhoWhereWhat they handle
HetznerEUHosting: your workbook, the documents you upload, and backups
Anthropic, OpenAI, GoogleUSDrafting answers, and council activities, which use all three
ExaUSWeb research, when an activity runs it
OpenAIUSThe search index across your workbook
ResendUSAccount and notification email

Your own API keys

After the alpha

Not in the private alpha. On paid plans after it, your organisation can connect its own key for Anthropic, OpenAI or Google, so generation runs under a contract your company already holds, with a provider it has already cleared.

What it does not change: our servers still make the call, so your material still passes through Scaffold. Three things stay on our accounts: the search index (OpenAI), web research (Exa), and council activities, which call all three providers and so need all three of your keys.

Kept apart from everyone else's

Each organisation's data is separated inside the database itself, not only by the app, so a request made for one organisation cannot read another's. Before the alpha opened, the whole codebase went through an automated OWASP security audit, and all 35 confirmed findings were fixed.

No trackers in the app

The Scaffold app carries no advertising. At launch it carries no third-party analytics either: what we measure is measured in our own database, in the EU. This website is separate, and uses Google Analytics, which you can refuse in the cookie banner.

During the alpha

The alpha is a test of the product, not a finished service, and it is by invitation: no price, no card, no self-serve sign-up. Two limits on what to put in: no special-category data, and no third-party material you are not free to share. The terms you accept when you join carry the detail.

Private alpha. No price, no card.

Everything above holds from your first day in the alpha, except your own API keys, which come after it.