Last updated: June 2026
Your documents contain some of the most sensitive information about your company: who has authority, what they can do, what the ownership structure looks like, and how decisions are made. We designed sanctor around one principle: your data stays with you.
Your provisions, documents, classifications, people records, role assignments, votes, resolutions, and all governance content are stored in your browser's local storage on your device. This data does not travel to or through sanctor's servers.
We chose this architecture deliberately. Your data is too sensitive to store on a third-party server, regardless of how well that server is protected. By keeping it on your device, the attack surface is reduced to your own device security, which you already control.
Two things only.
Your account credentials: email and hashed password, managed by our authentication provider with industry-standard encryption.
Your subscription status: plan, billing cycle, and payment status, managed by Stripe with PCI-compliant infrastructure.
That is all. No governance content. No provisions. No documents. No people data. No votes. No resolutions.
When you classify a provision, your browser sends the text directly to Anthropic's Claude API using your own API key. This call goes from your browser to Anthropic. It does not pass through sanctor's servers. We never see the content of your provisions.
Your API key is stored encrypted in your browser's local storage. It is not transmitted to or stored on our servers.
Anthropic processes your provision text according to their data handling policies. We recommend reviewing Anthropic's security documentation for details on how they handle API requests.
All communication between your browser and our authentication and billing services is encrypted using TLS. Your account password is hashed using a one-way hashing algorithm and is never stored in plain text. Your Claude API key is encrypted at rest in your browser's local storage.
When the system sends you a notification (email or SMS), the notification contains the minimum information necessary to inform you of a governance action. For example: "A vote is required" or "A deadline is approaching." The full details of the governance action are accessible only by logging into the application. Sensitive governance content is never included in notification text.
The audit trail extension logs every governance action taken in your workspace. This log is stored locally with all your other data. It is not transmitted to our servers. The audit trail is immutable within the application: entries cannot be edited or deleted through the interface.
Since your governance data lives on your device, your data security depends on your device security. We recommend:
If you discover a security vulnerability or have a concern about the platform's security, contact us immediately at security@sanctor.io. We take all reports seriously and will respond within 48 hours.