Skip to content

Security

Security & Compliance

1.About this page

Security questions or questionnaires: admin@piramade.com

Customer Content refers to the documents a Piramade customer firm makes available to Piramade, and everything we derive from those documents (extracted text, summaries, metadata, embeddings, and search indexes).

The Services refer to the Piramade platform, being the Piramade web application together with any software we provide for your firm to install on its own systems, including the Piramade Connector.

2.Piramade security summary

  1. 2.1A read-only Connector syncs the folders you choose. The files on your server remain unchanged by Piramade; this is a deliberate Piramade design decision to eliminate the risk of changes to your files.
  2. 2.2Your Customer Content is stored and processed by Amazon Web Services (AWS) in Australia (primarily AWS Sydney, ap-southeast-2*; encrypted backups in AWS Melbourne, ap-southeast-4*).
  3. 2.3The AI models used by Piramade run on Amazon Bedrock inside our AWS environment. Your Customer Content is never sent to an external AI provider, nothing is retained by the Amazon Bedrock AI models after processing, and no models are trained on your data.
  4. 2.4All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), and each customer’s data is separated and access-controlled.
  5. 2.5All Customer Content will be deleted within 90 days of termination of the Services. Certification of deletion can be provided on request.

3.How your data flows

  1. 3.1Sync: The Piramade Connector on your network reads only the folders you select. It is read-only, connects outbound only (no inbound connections, no firewall changes), and authenticates with short-lived, tenant-scoped upload credentials that can only access your own company’s data. You can revoke the Connector’s network access at any time.
  2. 3.2Encrypted copy: Piramade puts an encrypted copy of synced files in our AWS environment in the AWS Sydney region (ap-southeast-2*) to process, index and serve your team’s searches. The original files on your file server remain unchanged and are the source of truth at all times.
  3. 3.3AI: When AI features are used, Customer Content is processed by Amazon Bedrock within our own AWS environment in region AWS Sydney (ap-southeast-2*). Your Customer Content is not sent to an external AI provider, nothing is retained by the Amazon Bedrock AI models after processing, and no models are trained on your data. The Piramade system architecture has been deliberately designed so that Customer Content does not leave our AWS environment for AI processing.

4.Data hosting & residency

Customer Content is hosted by AWS in Australia: primary storage and processing in AWS Sydney (ap-southeast-2*), with encrypted backups in AWS Melbourne (ap-southeast-4*).

*If your company has specific alternative data residency requirements, please email admin@piramade.com and we can review implementation options.

www.piramade.com and the Piramade web application are currently delivered through Vercel’s global network, which does not store Customer Content.

5.Data retention

What Piramade retains

  1. 5.1Encrypted copies of your files
  2. 5.2Extracted text and search indexes
  3. 5.3User conversations, account data, and usage logs for platform operations

What AI providers retain

Nothing. The AI models used by Piramade run on Amazon Bedrock inside our AWS environment. Your Customer Content is never sent to an external AI provider, nothing is retained by the Amazon Bedrock AI models after processing, and no models are trained on your data.

All Customer Content will be deleted within 90 days of termination of the Services. Certification of deletion can be provided on request.

6.Permissions & access

  1. 6.1Your company’s users sign in with individual, invite-based accounts; multi-factor authentication is supported.
  2. 6.2User access is role-based, and each user’s data is separated and access-controlled at the database level.
  3. 6.3The Piramade Connector’s credentials and scope are defined by your company’s administrators. Company administrators can revoke the Connector’s network access at any time.
  4. 6.4Authorised Piramade staff have access to Customer Content to provide the Services and related support, subject to confidentiality obligations.

7.Subprocessors

The subprocessors used by Piramade and the extent of their access to Customer Content are summarised in the table below.

SubprocessorStores Customer ContentPurposeRegion
Amazon Web Services (AWS)YesHosting, file storage, AI (Amazon Bedrock)Australia
SupabaseYesDatabase and sign-in processesAustralia
VercelNo*www.piramade.com and Piramade web applicationGlobal
SentryNoError monitoringEU
PostHogNoProduct usage analyticsEU

*Vercel serves the web application, so Customer Content transits it when your users search; it is not stored there.

We give customers advance notice before any change to subprocessors that handle Customer Content.

8.Certifications

  1. 8.1Infrastructure — AWS is ISO 27001 and SOC 2 certified and IRAP-assessed; Supabase is SOC 2 Type II and ISO 27001 certified.
  2. 8.2Privacy — we operate under the Australian Privacy Act 1988 and the Australian Privacy Principles, and participate in the Notifiable Data Breaches scheme.
  3. 8.3Security questionnaires are completed on request. Please send to admin@piramade.com.

9.Data deletion & portability

The files on your server remain unchanged by Piramade; termination of the Services does not affect the files on your server.

All Customer Content will be deleted within 90 days of termination of the Services. Certification of deletion can be provided on request.

Requests to access, correct, or delete personal information are handled in line with the Privacy Act.

10.Vulnerability disclosure & incidents

If you discover a security vulnerability, report it to admin@piramade.com. We acknowledge reports promptly, keep you updated through investigation, and coordinate any disclosure after a fix is deployed. In the event of a security incident affecting customer data, we notify affected customers without undue delay.

This page was last modified on 17 August 2026 · Version 3.3.