Trust
AI and your data
Arthat Vault preserves your originals, evidence and context. When cognitive work is needed, a connected AI you choose does that work under a limited, versioned instruction. This page explains the boundary — including what is live and what is still landing.
1. Arthat Vault keeps; your chosen AI interprets
Arthat Vault is the system that stores the original, records where it came from, controls access, and keeps derived context linked back to its source. It is not meant to put a hidden Arthat Vault model between you and every file.
When an item needs work such as description, extraction, tagging or embedding, Arthat Vault can offer that work to a connected AI you chose. The request is governed by a versioned processing contract: a bounded instruction that names the source, the permitted task, the expected result and the rules for writing it back. Arthat Vault checks the result and records its source and processing history. The AI does the cognitive work; Arthat Vault remains the evidence and context authority.
If no suitable AI is connected or available, the original should still be kept. Processing can wait; storage must not depend on a model call succeeding.
2. Private is decided before capture
Private is a choice made before content enters a processing path. A Private item may be stored in your vault, verified for integrity and shown to you, but its contents are not dispatched to a connected AI. It is searchable by the limited information kept locally for that purpose, such as its title.
The processing runtime checks this more than once: before source content is fetched, again immediately before dispatch, and again before a returned result can be applied. Changing an item to Private withdraws its searchable body and earlier derived index from the active view.
3. Who may receive data
- Cloudflare R2
- Stores file bytes for Arthat Vault. It is storage infrastructure, not a model doing interpretation.
- Supabase
- Stores accounts, item records, searchable context, permissions, processing records and audit data.
- An AI you connect
- Receives only the non-Private source and bounded task that the applicable grant and processing contract allow. The provider and model depend on the connection you choose.
We will not quietly substitute a different provider for a connection you selected. A future Arthat Vault-operated provider option must identify the provider and purpose before your content is dispatched.
4. Training and provider terms
Arthat Vault does not sell your vault or use it to train an Arthat Vault model. We do not intentionally send your content to another company for advertising or model training.
A connected AI provider has its own retention, privacy and training terms, which may vary by product, account type, region and settings. Those are the provider’s promises, not ours, so we will not claim that every provider never trains on or retains submitted data. Review those terms before connecting it. Arthat Vault’s job is to show which connection is involved and limit what it receives.
5. Grants, logs and taking access back
A connected assistant starts without a vault-wide right to read. Its current grant, the item’s current privacy state and any pause switch are checked when it asks Arthat Vault for something. Arthat Vault records connected-assistant access in the audit log; if the required audit entry cannot be written, the read should fail rather than become invisible.
- Removing a grant or pausing a connection stops later reads through Arthat Vault.
- Moving an item to Private removes it from connected-AI access and prevents later processing dispatch.
- Deleting an item removes it from active retrieval and places it in trash under the retention rules on the Privacy page.
This page separates current behavior from work that is landing or planned. None of it is an audited guarantee. Arthat Vault has not completed independent assurance of these claims. We hold no SOC 2, ISO 27001, or other security certification. A status box calls out an incomplete or transitional capability instead of asking you to assume it is already live.
