SureMatters

Security overview

Version 0.3 (public summary) · Pending legal review

SureMatters is built local-first. This is the short version of how the products work and how you can check it yourself.

This is the public summary. The full Security Architecture — component detail, key management, incident response — is available to buyers on request from policy@surematters.com.

Where your documents live

On your own computer. SureRedact runs there entirely, and so does SurePrepare. (A helper service for source systems SurePrepare cannot read directly is designed but not yet built; when it ships it will run in your own cloud, under your own credentials.)

Your documents do not transit our infrastructure under any tier or any add-on, and we do not send them to OpenAI, Anthropic, or any other AI service.

Four commitments, built into the architecture

These are structural facts, not policy assertions.

  1. You make every final redaction decision. There is no automatic “apply all” path in the software. Every applied redaction is an explicit operator action, recorded with timestamp, identity and before-and-after state.
  2. Your documents stay inside your boundary. No code path sends document content to us or to any AI service.
  3. You control what leaves your machine. The only thing transmitted is an error report when something goes wrong, and you can switch it off — you are asked on first run. Operational records stay on your machine, where you can see them and clear them.
  4. AI assistance in anything we send you is labelled, and a named person has reviewed it.

What we run

Very little, deliberately. A static website, and the signing keys for our releases. We do not operate a telemetry service, a licence-verification service, an update service or a customer portal. Licences are issued by hand; you download releases from the website when you choose to.

There is very little attack surface on our side, because there is very little of our side.

Integrity you can check

How to verify it yourself

Drafted with AI assistance and reviewed by a named person, per our AI Policy. For the full Security Architecture document, write to policy@surematters.com. Accuracy concerns to security@surematters.com.