SureMatters

By Simon (drafted with AI assistance) · Published 9 May 2026

Why we don’t send your documents to OpenAI

SureMatters runs locally. Your customer documents do not transit our infrastructure under any tier. This is what that commitment means in practice and why we won’t walk it back.

A school office manager I spoke to last month described her existing redaction workflow: open the PDF in Acrobat, manually box-select every name, save as flattened, repeat for the next document, twenty times, lose the audit trail somewhere along the way, hope the data subject doesn’t notice the page numbers don’t line up. She told me she’d been to a vendor demo the week before where the answer was “our AI handles all of that — you just upload the documents.”

She declined the trial. Her data-protection officer had told her never to upload subject access request material to a cloud AI service. Her DPO is right.

This piece is about what we do instead and why we will not walk away from it.

The shape of the rule

SureMatters’ position is uncomplicated and contractual: customer documents — the records you’re preparing for disclosure, your decisions log, your scope, the bundles you move between the two tools, your final disclosure pack — do not transit our infrastructure under any tier or any add-on. We do not send them to OpenAI. We do not send them to Anthropic. We do not send them to Google’s Gemini API, AWS Bedrock, Azure OpenAI, Cohere, Mistral, or any other third-party hosted AI service. This applies to SureRedact Free, SureRedact Professional, every SurePrepare SKU, and every Enterprise contract. There is no exception.

The product enforces this structurally. SureRedact runs entirely on your laptop, and so does SurePrepare — both are local-first desktop applications. Where SurePrepare pulls from a platform it does so through a connector; a helper service for source systems it cannot read directly is designed but not yet built, and when it ships it will run in your own cloud under your own credentials. The application’s outbound traffic is one thing only: an error report when something goes wrong, stripped of file paths and content on your machine before it is sent, and switchable off — you are asked on first run. Beyond that there is nothing, because there is no service on our side to send anything to. Operational records stay on your machine, where Settings shows you every one and offers a button to clear them.

Corrected 13 August 2026: the paragraph above previously said outbound traffic went to “three SureMatters-operated endpoints — software updates, licence verification, and telemetry”, described telemetry as “the operational counts we collect”, named Vault and Vaultless deployment modes for the connector helper, and dated a Microsoft 365 / Azure tenancy to 2027. We operate none of those three services and never have, no telemetry has ever been transmitted to us, and the helper is not built — so its eventual form may differ from any of that. The paragraph above is what the software actually does. The first paragraph also listed a Privacy Add-on that was withdrawn on 1 June 2026. See the Telemetry Transparency Document and the Security overview.

Source-code inspection confirms this. Network-level inspection on your own infrastructure confirms this. Our AI Policy commits to it in writing. Our Terms of Service make it contractual.

Why we make the rule

Three reasons, in increasing order of how much they bind us.

The first reason is your DPO is right. UK schools, GP practices, housing associations, NHS suppliers, and small public bodies are subject to UK GDPR / DPA 2018, the Caldicott principles where applicable, sector-specific regulators, and a procurement culture that treats data-handling as a default-deny posture. A SAR file contains the most sensitive personal data the organisation holds about a single person. Sending that file to a third-party AI service — even one with a published DPA, even one in the EU, even one with the right SCCs — adds a processor relationship, a transfer mechanism, an onward-sharing risk, and a notification scope your DPO has to assess. Most don’t have time to assess it; most won’t approve it; and if they do, the data subject’s right to information now includes “your data has been processed by [AI vendor] in [their region] for the purposes of [their model improvement, possibly].” That’s not a procurement-pack-friendly answer.

The second reason is the architecture should make the trust posture true, not just promise it. Every SaaS company can write “we take privacy seriously” on its homepage. Most can’t write “your documents do not transit our infrastructure” because they do, even with the best intentions, even with the strongest available encryption, even with the most defensible regional-residency promises. We can write that sentence because we built the product around the sentence. The architecture is the commitment. The legal language at /privacy and /terms — and the processor agreement available on request — documents what the architecture already does.

The third reason is we want to be useful in five years, not just at the next renewal. AI capability is improving rapidly. So is the regulatory environment around AI processing of personal data. The ICO’s AI guidance evolves. Article 22 case law evolves. The boundary between “vendor uses AI to help process customer data” and “vendor must establish a controller-controller relationship for the AI processing” will shift. We have no idea where it will land. What we do know is that not sending your documents to a third party sits comfortably outside whatever rules emerge. Building the company on a posture that survives regulatory drift is how we still exist in 2031.

What we do use AI for

We use AI in two layers. We are explicit about both.

In the products, we use rule-based detection patterns and on-device machine-learning detectors — and it is worth being precise about which is which, because most of it is not machine learning at all. SureRedact’s signature detector is a machine-learning model that runs on your own computer. The phone-number, email-address and credential detectors are rule-based: patterns, a phone-number parsing library, role-name lists, and entropy checks, with no model involved. All four look at every page and surface candidates for redaction. You confirm or reject every one. The detectors run on your laptop; the one trained model is bundled with the application; nothing about your documents leaves your computer through the detection layer.

In SurePrepare, the workflow is purely rule-based at launch — a 19-signal rule table looks at each record and assigns include / exclude / review verdicts based on rules you and we both can read. We deferred the AI-assisted layer that was originally planned for launch because the hardware fit and quality bar didn’t meet what we considered acceptable for a line-of-business audience. If we reintroduce AI assistance in a later release, it will run on your own device under a published quality-bar evaluation; it will not run via OpenAI.

In our company operations, we use Claude Code to draft documentation, write code, review pull requests, and triage early support tickets. Every customer-facing artefact produced with AI assistance is reviewed by a named human. We label AI-assistance on the marketing site, on the customer-success outbound channel, on release notes, and at the foot of every policy document including this one. Hiding agent involvement in our own customer communication would be inconsistent with the product’s own commitments to transparency on telemetry and detection. We accept the small operational cost.

What changes the rule

Nothing material to a customer changes the rule without notice. The AI Policy §8 commits us to a customer-facing notice on the marketing site within 10 working days of any material change, and a direct email to current customers at least 30 days before the change takes effect, with the option to terminate the contract pro-rata. If we ever introduced a managed multi-tenant variant of SurePrepare that processed customer documents on SureMatters infrastructure, the AI Policy and the Terms would change before that product launched, customers would see it, and the change would carry SCCs / IDTAs / a published DPIA appropriate to the new processing.

But we are not building that product. The product is local-first by design. The trust posture is structural, not promised. AI assists us in running the company, under senior human review on every customer-facing artefact; AI does not process customers’ documents. We sell on the rule, we build on the rule, we honour the rule.

If your DPO has questions about how this works in practice, write to policy@surematters.com. We answer within five working days.


Simon is the founder of SureMatters. This post was drafted with Claude assistance and reviewed by Simon before publication, per the AI Policy §3.4.

← Back to blog