Security Policy

This Security Policy describes the technical and organizational measures Attaché Desk Ltd ("Attaché Desk", "we", "us") applies to protect data when you use our platform, website, APIs, desktop applications, add-ins, and related services (collectively, the "Services").

Attaché Desk is built for diplomatic institutions — missions, ministries, and IGO practitioners — where the confidentiality of drafts, counterpart profiles, dossiers, and position papers is non-negotiable. Security is not a feature; it is a foundational design constraint.

This Policy forms part of your agreement with Attaché Desk. Capitalized terms not defined here have the meaning given in the applicable Subscriber Agreement or Terms of Service.

1. Certifications and Audits

1.1 Current certifications

Attaché Desk pursues and maintains independent third-party audits of its information security management system on at least an annual basis. Current and planned certifications:

FrameworkStatus

GDPR-aligned processing - Active

SOC 2 Type II - Target: 2027

ISO 27001 - Roadmap

Audit reports and compliance summaries are available to Subscribers on request, subject to execution of a confidentiality agreement. See Section 8.

1.2 Ongoing review‍ ‍

Where Attaché Desk decides to discontinue a particular audit framework, it will adopt an equivalent industry-recognized alternative and notify Subscribers accordingly.

2. Data Residency

2.1 EU hosting

All Subscriber Content — including drafts, dossier materials, agreed-language corpora, counterpart profiles, and exported documents — is hosted exclusively in data centres located within the European Union. Attaché Desk does not replicate Subscriber Content to servers outside the EU without explicit written agreement.

2.2 AI model providers

The Services integrate third-party AI model APIs (currently including Anthropic, Mistral AI, Google Gemini, and Perplexity). Prompts and outputs submitted to these APIs may be processed on infrastructure outside the EU. All such processing is governed by contractual no-training terms — see Section 3 below. We continuously review provider data handling commitments and maintain Standard Contractual Clauses or equivalent transfer mechanisms with each provider.

2.3 Classification routing

When a document or session is marked Restricted or Confidential within the platform, live external web search and retrieval is automatically disabled. Only internal dossier, corpus, and agreed-language sources are queried. This classification gate is enforced server-side and cannot be overridden by end users.

3. No Training on Your Data

Attaché Desk maintains contractual no-training terms with every AI model and infrastructure provider used in the Services. This means:

  • Your drafts, dossier contents, uploaded documents, prompts, and outputs are never used to train, fine-tune, or improve any AI model operated by Attaché Desk or its providers.

  • Model providers process your data solely to return a response to the submitted request and are contractually prohibited from retaining or using Subscriber Content for model development.

  • This commitment applies regardless of which underlying model (Anthropic Claude, Mistral, Gemini, Perplexity) processes a given request.

We re-confirm no-training terms with providers on each contract renewal and upon any material change to provider terms.

4. Encryption

4.1 Data at rest

Subscriber Content and all associated metadata are encrypted at rest using AES-256 (or stronger) encryption. Encryption keys are stored separately from data and are rotated on a defined schedule.

4.2 Data in transit

All data in transit between your browser, application, or add-in and our platform is encrypted using TLS 1.2 or higher. Connections using weaker protocols are rejected.

4.3 Key management

Encryption keys are managed via hardware security modules (HSMs). Key rotation is performed on a scheduled basis. Encryption keys are logically separated from the data they protect.

5. Tenant Isolation

Every Subscriber account is logically isolated from all other accounts through row-level security (RLS) enforced at the database layer. This means:

  • Queries from one Subscriber account cannot access data belonging to another account, regardless of application-layer configuration.

  • Dossiers, drafts, cleared documents, counterpart profiles, and agreed-language libraries are siloed per tenant.

  • RLS enforcement is validated as part of our regular security review cycle

6. Access Controls and System Security

6.1 Principle of least privilege

Attaché Desk personnel access to production systems is governed by the principle of least privilege. Access is granted on a role-specific, need-to-know basis and reviewed at least quarterly.

6.2 Authentication requirements

All personnel accessing production infrastructure must authenticate using a unique user ID, multi-factor authentication (MFA), and a secure encrypted connection. Shared credentials and password reuse are prohibited.

6.3 Staff access to Subscriber Content

Attaché Desk personnel will not access Subscriber Content except:

  1. To provide or support the Services (e.g., incident response at the Subscriber's explicit request); or

  2. As required to comply with a law or binding order of a competent governmental authority

Any such access is logged in the append-only audit log described in Section 7.

6.4 Endpoint security

Staff devices accessing production systems use encrypted storage and are equipped with endpoint detection and response (EDR) tools that monitor for suspicious activity and malicious code.

6.5 Network security

Our cloud environment is protected by industry-standard firewalls, intrusion detection systems, and network segmentation. Threat detection tools operate with frequent signature updates.

6.6 Penetration testing

Attaché Desk engages an independent third-party security firm to conduct penetration tests of the Services at least annually. Summary results are available to Subscribers on request under a confidentiality agreement. See Section 8.

6.7 Vulnerability remediation

Identified vulnerabilities are triaged and remediated based on severity:

SeverityTarget remediationCriticalWithin 48 hoursHighWithin 7 daysMediumWithin 30 daysLowWithin 90 days

7. Audit Logging

Attaché Desk maintains an append-only audit log covering material platform events, including:

  • User authentication (sign-in, sign-out, failed attempts);

  • Document creation, editing, export, and deletion;

  • Dossier access and modification;

  • Classification changes applied to sessions or documents;

  • Clearance queue actions;

  • Administrative changes (user provisioning, access changes);

  • AI prompt submissions (metadata level only — not content).

Audit logs cannot be modified or deleted by Subscribers or Attaché Desk staff and are retained for a minimum of 12 months. Enterprise accounts may request extended retention up to 7 years. Logs are available to Subscribers via the platform's audit export feature or on request.

8. Screen Shield and Vault Lock

Screen Shield limits on-screen content rendering to prevent unauthorized capture through screen-sharing applications or browser plugins, where technically supported by the operating environment.

Vault Lock provides document-level access controls within the platform, enabling Subscribers to restrict access to sensitive dossiers or drafts to named users or roles, independently of general account permissions.

Both features are configurable by Subscriber administrators.

9. Incident Detection and Response

9.1 Security incident notification

If Attaché Desk becomes aware of a breach of security leading to the unauthorized destruction, loss, alteration, disclosure of, or access to Subscriber Content ("Security Incident"), we will:

  1. Notify the affected Subscriber without undue delay, and in any case within 72 hours of becoming aware, to the security contact address specified in the Subscriber Agreement;

  2. Take prompt steps to contain, investigate, and mitigate the incident;

  3. Preserve relevant security logs for at least 12 months

9.2 Incident communications

Incident notifications will include, to the extent known: the nature of the incident, categories and approximate volume of data affected, likely consequences, measures taken or proposed, and a contact point for further information. Notification does not constitute an admission of liability.

9.3 Scope limitation

Where Attaché Desk personnel cannot access Subscriber Content (e.g., due to encryption at the application layer or administrator-only access configurations), we may not be able to confirm the type or volume of Subscriber Content affected. We will clearly state any such limitations in our notification.

10. Physical Data Centre Controls

Attaché Desk does not operate its own physical data centres. Our cloud environment is provided by tier-1 cloud service providers with EU data centres. We require that each provider maintains at minimum:

  • SOC 2 Type II audit certification and ISO 27001 certification (or equivalent);

  • Physical access controls with ID verification at all facility ingress points;

  • CCTV surveillance;

  • Adequate fire detection and suppression systems;

  • Climate control and uninterruptible power supply;

  • Redundancy and backup systems sufficient to meet our availability commitments.

‍ Attaché Desk may maintain registered offices for corporate purposes. No Subscriber Content is stored or hosted at any Attaché Desk office.

11. Administrative Controls

11.1 Security training

All Attaché Desk personnel complete security awareness training at onboarding and at least annually thereafter. Training is updated to reflect current threat landscapes.

11.2 Confidentiality obligations

All personnel are subject to binding confidentiality obligations covering Subscriber Content and other non-public information as a condition of employment or engagement. ‍

11.3 Access review

Access privileges of personnel to production systems are reviewed at least quarterly. Access is revoked promptly upon separation or role change.

11.4 Sub-processor security

Attaché Desk ensures that sub-processors and vendors who access Subscriber Content maintain security measures consistent with this Policy and with the applicable Subscriber Agreement

12. Subscriber Responsibilities (Shared Security Model)

Security on the Attaché Desk platform is a shared responsibility:

  • Credentials: You are responsible for managing and protecting your account credentials. Credentials must not be shared with unauthorized parties. Report any suspected compromise to security@attachedesk.ai immediately.

  • Classification: You are responsible for applying appropriate classification designations within the platform for your materials. Attaché Desk enforces classification gates based on the designations you set.

  • Data authorization: You are responsible for ensuring that content uploaded to the Services is authorized for processing in an AI-assisted environment consistent with your organization's classification and information security policies.

  • Browsers and devices: You are responsible for keeping browsers, operating systems, and devices used to access the Services updated and appropriately secured.

  • User provisioning: Administrators are responsible for promptly revoking access for departing or unauthorized users.

13. Compliance and Documentation

Upon request and at no additional charge, Attaché Desk will provide Subscribers with:‍ ‍

  1. Our current third-party audit certificates (where available);

  2. A summary of our most recent penetration test results;

  3. Our standard data flow diagrams for the Services;

  4. This Security Policy and our Data Processing Agreement.

‍ Third-party auditors engaged by Subscribers must execute a separate confidentiality agreement with Attaché Desk prior to reviewing any audit documentation. Attaché Desk may reasonably object to an auditor that is not suitably qualified or that has a conflict of interest.

14. Contact

To report a security vulnerability or incident, or for questions about this Policy:

security@attachedesk.ai

For responsible disclosure, we welcome reports from security researchers at the address above. We commit to acknowledging all reports within 48 hours and providing a substantive response within 7 business days.

Attaché Desk Ltd
Dublin, Ireland
European Union