Security & Deployment

Your documents, your perimeter.

This page is written for the people who say no: IT, security, and compliance. It describes exactly where documents go, what is stored, and what your institution controls.

Deployment

Three ways to run Sabiá

Processing always runs server-side — nothing runs on the analyst's machine, and there is no Excel plugin to clear through bank IT. What changes between tiers is where that server sits.

TierFor whomHow it runs
Managed clouddefaultPilots and most clientsDocuments are uploaded to our hosted environment in the São Paulo region and processed there. Fastest to deploy — zero client install.
Private cloud / VPCInstitutions with cloud tenancy requirementsThe same software deployed inside your cloud tenant. Documents never leave your account boundary.
On-premiseSecurity-sensitive work (IPOs, confidential M&A)Deployed inside your perimeter, including the model. Documents — which in Brazil routinely include pre-IPO financials — never leave your environment.
Guarantees

Non-negotiables

Immutable citation log

Every extracted field stores (document, page, bounding box, raw text, confidence score, timestamp, analyst action). Overrides never overwrite — they append. This is the audit trail your compliance team reviews.

Your documents never train models

Client documents are used to serve your extractions — nothing else. No training, no cross-client pooling.

Per-client isolation

Each institution runs in an isolated workspace, encrypted in transit and at rest, with role-based access control and retention policies your admin configures.

Supervision without exposure

Supervisors see usage telemetry — workload, review flags, spend — never the underlying client documents.

LGPD

LGPD & data residency

Processing in Brazil

The managed-cloud tier runs in the São Paulo region. Where data crosses borders (e.g. model inference), it is disclosed and controllable — including fully in-country options.

LGPD alignment

PII detection and masking on uploaded documents, DPA on record, configurable retention with auto-purge, and a named contact for data-protection matters.

Cross-border control

The admin dashboard shows, per dataset, where data lives and whether it leaves Brazil — so your compliance team audits residency instead of trusting a slide.

Certification roadmap

SOC 2 Type II preparation is on our roadmap ahead of bank-wide deployments. Security documentation — architecture, data flows, and the citation-log design — is available today for your IT team's review.

Have your IT team put us through review.

We'd rather answer the hard questions before the pilot than after.

Talk to usDownload one-page summary (PDF)