Security

Where Your Data Actually Lives

De-Cloud AI runs in two places. The AI model runs on hardware you own, and a small set of well-established cloud services host the web application around it. Here is every vendor in the system, and exactly what each one holds.

Where each kind of data lives

DataWhere it lives
Every prompt your staff sendYour AI server. Never transmitted off it.
Every answer the AI generatesYour AI server. Never transmitted off it.
The AI model itselfYour AI server, run by Ollama.
Document conversion and the search indexYour AI server.
Uploaded files, at restCloudflare R2, encrypted.
Accounts and chat historyNeon Postgres, isolated per organization.
Password resets and invitationsResend.

Your AI server (Ollama)

Source: ollama.com | Owner: your organization

  • Runs open-source models locally through Ollama. No model provider account, API key, or outbound request is involved in producing an answer
  • Prompts, answers, document conversion, and the search index are all produced on this machine
  • Sits in a lockable space on your own network, on hardware your organization owns outright
  • Patched, updated, and health-monitored remotely by NextWrite, with no access to your prompts, your answers, or your documents

This is what makes De-Cloud AI different from every other option. Because the model runs here, no outside AI company receives your prompts, your documents, or anything generated from them.

Vercel

Source: vercel.com/security | Owner: Vercel, Inc.

  • SOC 2 Type II, GDPR, CCPA compliance
  • Encryption in transit and at rest
  • Identity & access management, secure global infrastructure
  • Continuous scanning, third-party audits, incident response

We inherit Vercel's secure hosting and CI/CD infrastructure, ensuring NextWrite deployments are monitored and protected against threats.

Neon

Source: neon.com/security | Owner: Neon.tech

  • SOC 2 Type II compliance
  • Encryption at rest and in transit, role-based access
  • Network isolation, monitoring, automated failover

We inherit Neon's secure managed Postgres environment for NextWrite's data storage and orchestration.

Cloudflare R2

Source: cloudflare.com/trust-hub | Owner: Cloudflare, Inc.

  • SOC 2 Type II, ISO 27001, GDPR compliance
  • Encryption in transit and at rest
  • Scoped, short-lived access credentials rather than shared keys
  • DDoS protection and continuous monitoring

Uploaded files are stored here. Conversion and indexing happen on your own AI server, so Cloudflare holds the stored file and never the searchable content derived from it.

Resend

Source: resend.com/docs/security | Owner: Resend, Inc.

  • SOC 2 Type II, GDPR compliance
  • TLS 1.3+ encryption, 30-day global backups
  • Annual pen testing, vulnerability scans, endpoint protection
  • MFA for all staff, least-privilege access model

We inherit Resend's secure email delivery pipeline, ensuring messages generated by NextWrite are delivered with enterprise-grade protection.

NextWrite's Layer of Security

  • Role-based access control (RBAC): only authorized users can access sensitive data.
  • Audit logging: all AI interactions and outputs are traceable and reviewable.
  • Human-in-the-loop checkpoints: staff make final decisions, reducing AI misuse risks.
  • On-premises by default: the AI model runs on hardware you own, so the most sensitive processing never leaves your building.