Skip to main content

Security, privacy and data

How your data is handled.

Vera, Clara, and Lucia work in the AI workspace you choose. Mparanza-hosted services and other external destinations are separate.

Vera + Clara · Video

How Vera and Clara handle data.

See the difference between local preparation, model processing in your selected workspace, and a service hosted by Mparanza.

Watch on YouTube

Your selected AI workspace is the main boundary.

Data needed for the work may enter the model context of the OpenAI ChatGPT or Codex account, or the Anthropic Claude or Cowork account, that you select. Mparanza is not a separate recipient of ordinary plugin work.

Your computer Local files · local Python · local outputs
Your selected AI workspace OpenAI ChatGPT or Codex · Anthropic Claude or Cowork

Ordinary plugin work sends no client or work content to Mparanza.

Local preparation is useful, not automatic anonymisation.

Local Python can sort, calculate, reconcile, filter, aggregate, and create outputs. A workflow may use it before a model step when that improves the work.

The plugins do not automatically anonymise or pseudonymise data. Names, documents, original language, and case facts remain when they are useful for the professional purpose.

The detailed boundary belongs to the workflow.

Each workflow can use data differently. Its own page explains the operational sequence: what the model sees, what code processes, and when the process stops. This page does not duplicate those workflow-specific statements.

Never put passwords, API keys, authentication cookies, access tokens, or session material in prompts or files the selected AI workspace can read.

Vera records the boundary of every substantive run.

After every substantive Vera run, a compact report records each model-visible phase in the workflow's natural units. It distinguishes the source extent available, what code processed locally, what was visible to the model, which part was never visible to the model, why the context was needed, and the available evidence basis. When the host can write files, Vera keeps a JSON receipt and a Markdown version in that run's output; otherwise it shows the report in chat and says that no durable receipt was created. The locally processed total and the never-model-visible part overlap; they are not alternative categories to add together.

A possible narrower code path appears only when evidence from the run supports it and identifies a safeguard for analytical quality. A complete relevant document or population can be the correct minimum. The report is not network monitoring, a provider attestation, a DPIA, a legal opinion, or GDPR certification; a recorded hash binds a receipt to bytes but does not prove provider-side delivery.

Each durable run automatically sends Mparanza only a random receipt ID, the Vera version, and the digest of the local report. Mparanza adds its server time and Ed25519 signature and retains those proof fields without the report, client data, filenames, source content, or source-document hashes. The resulting HTML can be sent to a customer, printed as PDF, and checked on the public verification page. This proves existence, server time, and report integrity only; it does not independently prove who submitted the digest. If the receipt service is unavailable, the work and local report remain complete and the request stays pending for retry.

Connectors and sends use their own destination.

A connected app, public search, portal, or send action is used only when that route is part of the selected work. The destination's terms and controls apply separately.

Using an external destination does not make Mparanza the recipient. The workflow or point-of-use notice identifies a Mparanza-hosted route when one is involved.

Mparanza-hosted services are a separate boundary.

When a function uses a Mparanza-hosted service, the content needed for that service reaches Mparanza-controlled systems. Hosted interviews, voice capture, and retail data are examples.

The notice shown where that service is used states what reaches it and the applicable access, retention, and deletion arrangement.

Verify the position.

You do not have to rely on the claim alone.

One global boundary. Process details stay with the process.