We would rather tell you what is missing than let a claim stand unchallenged until your own due diligence finds it.
Security posture
Neither certification has a target date scoped yet.
A data processing agreement is available on request, and we will complete a CAIQ or SIG style vendor questionnaire and sign a security addendum with incident response terms as part of an Enterprise conversation.
Retention
api_key_transactions rows are purged on a time to live index rather than kept indefinitely.GET /audit and GET /usage are retained for billing, so your own usage history stays available to you.Breach process
We notify affected customers within 72 hours of confirming a breach that affects their data or their account. That clock starts at confirmation, not at first suspicion, because an unconfirmed alert is not yet something we can respond to responsibly. What we send at that point: what is known so far, what we have already done, and what you should do on your side. A fuller report follows once the investigation is complete.
Subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| AWS | Hosting, storage and compute | ap-south-1 (Mumbai) |
| OpenAI | AI analysis and adjudication, under a zero retention API usage agreement | API, not self hosted |
| Razorpay | Payment processing for credit purchases and subscriptions | India |
Support
support@courtmesh.ai for every plan, including security questions and incident reports. Enterprise customers get a named contact in addition to this address.
No SLA is published today, stated plainly rather than implied by silence. See Request ids and support in the API documentation for what to include when you write to us about a specific call.