Archevi
Security & Privacy

Your family's privacy. Guaranteed.

AI-powered document intelligence with zero exposure of your personal information. Your documents stay on our servers. The AI only sees anonymized surrogates -- never your real data.

Canadian data residencyAES-256 encryptionZero AI training on your dataPasskey authentication

Privacy-by-design, not privacy-by-opt-out

Most AI apps use your data for training unless you turn it off. Archevi never sends your real data to AI -- by architecture, not just by policy.

Boundary Anonymization

Personal information is automatically detected and replaced with realistic surrogates before cloud AI processing. Names become fake names. Emails become fake emails. The AI never sees the real thing.

Powered by Microsoft Presidio -- industry-standard PII detection used by enterprises worldwide.

Hard Redaction

Highly sensitive data like Social Insurance Numbers and credit card numbers are not anonymized -- they are blocked entirely. If detected, the query is rejected before it reaches any external service.

Two layers: regex pattern matching (instant) + Presidio NER (deep analysis).

Canadian Data Residency

Your documents are stored on Canadian infrastructure and never leave our servers. Only anonymized query text reaches cloud AI providers -- and even that contains no real personal information.

PIPEDA compliant. Your files stay in Canada.

How boundary anonymization works

The AI sees surrogates, not your family. Here is what happens when you ask a question.

1

You ask

"What did John Smith say about Apple stock?"

2

Archevi detects entities

John Smith (PERSON), Apple (ORG)

3

AI receives surrogates

"What did Alex Johnson say about TechCorp Alpha stock?"

4

You see real names

"John Smith mentioned a positive outlook on Apple..."

The AI never knew you were asking about John Smith or Apple. It only processed surrogates. Your real data never left our servers.

What gets protected

Two strategies for two types of sensitive data.

Anonymized (Surrogates)

Replaced with realistic fakes so AI can still reason about context:

NamesJohn Smith → Alex Johnson
Phone numbers555-0123 → 555-9847
LocationsToronto → Halifax
OrganizationsApple → TechCorp Alpha

Blocked (Hard Redaction)

Detected and blocked entirely. The query is rejected before reaching any external service:

  • Social Insurance Numbers
  • Credit card numbers
  • Bank account numbers
  • Passport numbers
  • Driver's licence numbers
  • IBAN codes

AI providers we use and why

We chose AI providers with contractual no-training commitments. But we go further -- they only receive anonymized surrogates.

Groq

Processes anonymized queries with Llama language models.

  • Does not use data for model training
  • Zero data retention on inference
  • Only receives surrogates, not real data
Cohere

Powers semantic search and document retrieval with embedding models.

  • Does not use data for model training
  • SOC 2 Type II certified
  • Only receives surrogates, not real data

Authentication and infrastructure security

Multiple layers of protection from login to storage.

Passkey / WebAuthn

Passwordless authentication using FIDO2 passkeys. Phishing-resistant by design.

Two-Factor Authentication

TOTP-based 2FA with backup recovery codes. Required for sensitive operations.

Trusted Devices

Manage and review devices that have access. Revoke any device instantly.

Token Rotation

Refresh tokens are single-use and rotate on every request. Stolen tokens expire immediately.

Tenant Isolation

Database-enforced row-level security. Each family operates in a completely separate data partition.

Encryption

AES-256 encryption at rest. TLS 1.3 for all data in transit. No unencrypted data at any layer.

Family-isolated data

Every family on Archevi operates in a completely separate tenant. Your documents, conversations, anonymization vaults, and search history are invisible to other families.

  • Row-level security enforced at the database layer
  • No cross-tenant query paths exist
  • Role-based access within each family
  • Separate anonymization vaults per conversation

The Hudson Family

Completely separate

The Tremblay Family

Completely separate

Your Family

Your isolated vault

Standards and compliance

PIPEDA

Canadian privacy law

GDPR Ready

EU data protection

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

Security & privacy FAQ

Ready to secure your family's documents?

Join families who trust Archevi with their most important documents. Privacy-preserving AI included in every plan.

14-day free trial • No credit card required • Privacy protection from day one