Your family's privacy. Guaranteed.
Your family documents stay private and are stored in Canada. When you chat with the AI, your message is de-identified with surrogates before the language model sees it. Encrypted at rest, PIPEDA-compliant by design.
Your personal details are de-identified before the AI answers.
Privacy-by-design, not privacy-by-opt-out
Your privacy is not a setting you toggle on. It is built into every layer of how Archevi works, from how we store your files to how we process your questions.
Personal information is automatically detected and replaced with realistic surrogates before the AI answers. Names become fake names. Emails become fake emails. The AI that answers your questions never sees the real thing.
Powered by Microsoft Presidio. Industry-standard PII detection used by enterprises worldwide.
Highly sensitive data like Social Insurance Numbers and credit card numbers are not anonymized. They are blocked entirely. If detected, the query is rejected before it reaches any external service.
Two layers: regex pattern matching (instant) + Presidio NER (deep analysis).
Your documents, backups, and search index are stored on encrypted servers in Canada, with full PIPEDA compliance and GDPR-aligned data handling. When you chat with the AI, your message is de-identified with surrogates before the language model sees it.
PIPEDA compliant, GDPR-aligned. Your files are stored securely and never used for AI training.
How boundary anonymization works
The chat AI sees surrogates, not your family. Here is what happens when you ask a question.
You ask
"What did John Smith say about Apple stock?"
Archevi detects entities
John Smith (PERSON), Apple (ORG)
AI receives surrogates
"What did Alex Johnson say about TechCorp Alpha stock?"
You see real names
"John Smith mentioned a positive outlook on Apple..."
The chat AI never knew you were asking about John Smith or Apple -- it only ever processed surrogates, never the real names behind your question.
What gets protected
Two strategies for two types of sensitive data.
Anonymized (Surrogates)
Replaced with realistic fakes so AI can still reason about context:
John Smith -> Alex Johnson[email protected] -> [email protected]555-0123 -> 555-9847Toronto -> HalifaxApple -> TechCorp AlphaBlocked (Hard Redaction)
Detected and blocked entirely. The query is rejected before reaching any external service:
- Social Insurance Numbers
- Credit card numbers
- Bank account numbers
- Passport numbers
- Driver's licence numbers
- IBAN codes
AI providers we use and why
We chose AI providers with contractual no-training commitments. For chat, we go further: our language-model provider only ever receives anonymized surrogates.
Processes anonymized queries with Llama language models.
- Does not use data for model training
- Zero data retention on inference
- Only receives surrogates, not real data
Powers semantic search and document retrieval with embedding models.
- Does not use data for model training
- SOC 2 Type II certified
- Canadian company, based in Toronto
Authentication and infrastructure security
Multiple layers of protection from login to storage.
Passkey / WebAuthn
Passwordless authentication using FIDO2 passkeys. Phishing-resistant by design.
Two-Factor Authentication
TOTP-based 2FA with backup recovery codes. Required for sensitive operations.
Trusted Devices
Manage and review devices that have access. Revoke any device instantly.
Token Rotation
Refresh tokens are single-use and rotate on every request. Stolen tokens expire immediately.
Tenant Isolation
Database-enforced row-level security. Each family operates in a completely separate data partition.
Encryption
AES-256 encryption at rest. TLS 1.3 for all data in transit. No unencrypted data at any layer.
Family-isolated data
Every family on Archevi operates in a completely separate tenant. Your documents, conversations, anonymization vaults, and search history are invisible to other families.
- Row-level security enforced at the database layer
- No cross-tenant query paths exist
- Role-based access within each family
- Separate anonymization vaults per conversation
The Hudson Family
Completely separate
The Tremblay Family
Completely separate
Your Family
Your isolated vault
How we keep the platform safe
Every file uploaded to Archevi is automatically checked before it enters your vault. These scans are fully automated and do not involve human review of your documents.
Full details in our Acceptable Use Policy and Privacy Policy.
Three Trust Zones
Your data passes through isolated zones. Each one has a single job: protect what matters most.
Files upload over TLS 1.3 directly to Canadian servers. No intermediary CDN. No US hop. Your browser talks to Toronto.
TLS 1.3, AES-256 at rest, End-to-end encrypted transit
Before the AI answers, Presidio strips names, SINs, emails, phone numbers. What remains is structure without identity.
Microsoft Presidio, Regex hard blocks, SIN/credit card/passport never pass through
AI receives anonymized surrogates only. It answers questions about your documents without ever knowing who you are.
Groq: zero retention, no training. Cohere: SOC 2 Type II, no training
Not All “AI + Documents” Is Equal
Most AI tools process your raw data on US servers. Archevi was built differently from day one.
Typical AI document tools
Archevi
Your Document's Journey
From the moment you upload to the moment you ask a question, here is exactly what happens.
Standards and compliance
Not retrofitted for compliance. Built with it from the first line of code.
PIPEDA & GDPR
Privacy law compliant
GDPR Ready
EU data protection
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
SOC 2
AI provider certified
RLS
Row-level tenant isolation
Security & privacy FAQ
Privacy your family can verify, not just trust
Every family member gets AI-powered search, with your documents stored in Canada and chat de-identified before it reaches the AI. No ads, and no training on your documents.
Free plan available • No credit card required • Privacy protection from day one