Security model · two explicit data flows
Know where the document goes before you choose.
Integrity Scan stays on-device. AI Deep Review is a separate, opt-in workflow that sends the selected file through Ocolta's Cloudflare Worker and OpenRouter to a policy-eligible model endpoint.
Integrity Scan data flow
The shortest path is no path off-device.
1. You select a file
The browser grants this page temporary access only to the file you choose. Dragging or selecting does not automatically transmit it.
2. The browser reads bytes
JavaScript checks the binary signature, metadata strings, PDF structures, and optional user-entered arithmetic on your device.
3. The browser creates results
The review score, findings, SHA-256 fingerprint, and downloaded report are generated locally.
4. The tab owns the session
Results live only in page memory. Close or refresh the tab and they disappear unless you downloaded a report yourself.
AI Deep Review data flow
A deliberate upload with visible tradeoffs.
1. You choose and consent
The review does not start until you select a supported file, confirm you are authorized to submit it, and explicitly accept that it will leave your device.
2. Cloudflare receives and verifies the request
The selected file reaches Ocolta's Worker for in-memory validation and scanning. Turnstile separately verifies a security token and standard request information, including the connecting IP address.
3. OpenRouter routes the model request
Ocolta sends the full file and, for PDFs, the filename to OpenRouter and requests openai/gpt-5.6-terra. The request requires a ZDR, non-data-collecting endpoint that honors every parameter, the default service tier, and configured rate ceilings.
4. Retention controls have a documented boundary
OpenRouter says prompt/response logging depends on its account setting and that non-content request metadata is retained. Per-request endpoint controls do not prove the account setting. The chosen downstream endpoint remains subject to its legal and safety duties.
5. A short recovery copy protects delivery
Ocolta does not save the submitted document. For up to 24 hours it keeps the normalized model-authored report, any Deep Review+ corroboration appendix, versioned consent, and safe routing/usage metadata, while omitting the deterministic scan, its derived combined assessment, and the scan's structured filename, type, size, and SHA-256 fields. The appendix can retain model-extracted institution names, printed business addresses, domains or payroll descriptors, and public-source outcomes and URLs. Model-authored text and the appendix can repeat source-document information. Browser responses use no-store headers.
Document request data flow
The one place Ocolta can hold a document.
1. Two scoped link tokens
Each request has separate upload and requester-results links. The request database stores only token hashes, so a database read alone cannot rebuild either link. For newer requests, the Worker can rederive the requester token with its deployment secret for delivery email; Resend and mailboxes can therefore hold a usable requester link.
2. The scan runs on the server, not the sender's device
The uploader is the party whose document is in question, so a result computed in their browser would be attacker-controlled. Every finding the requester sees is produced server-side from the received bytes.
3. Retention is off unless the requester asks
By default the document is scanned and discarded; only the findings, filename, size, type, and SHA-256 fingerprint are kept. The recipient is told which applies before uploading.
4. Access cuts off before asynchronous deletion
Opt-in file download access ends fourteen days after upload. An hourly Worker sweep performs primary deletion. A checked-in R2 lifecycle configuration is provided for an operator to apply as an independent backstop, but this source audit did not verify that lifecycle as active in production; physical deletion may occur later. All links close after thirty days or immediately on cancellation, and Ocolta's request-database rows become purge-eligible fourteen days later.
5. Email copies have a separate boundary
Request emails name the requester and carry their address as reply-to. Delivery emails can include the filename, result summary, flagged-finding titles, and requester link. Database deletion does not remove copies held by Resend or the parties' mailboxes. Notes may not contain links, and sending is rate limited.
Provider boundary
Routing controls are not a substitute for a contract.
Ocolta's request restricts OpenRouter to downstream endpoints advertising Zero Data Retention and no data collection, but source code cannot verify OpenRouter's account-level prompt-logging setting or override a provider's legal obligations. The endpoint may change between requests; safe provider/model metadata is captured when reported.
Use AI Deep Review only with files you are authorized to share, remove personal data the review does not need, and use the local scan when external processing is inappropriate.
Read the full privacy notice or review the AI consent screen.
Practical safeguards
Use sensitive documents carefully—even locally.
- Analyze only documents you are authorized to review.
- Use a managed, patched browser and a trusted device.
- Avoid public or shared computers for applicant financial documents.
- Store exported reports under your organization’s retention policy.
- Remove unnecessary personal data before choosing AI Deep Review.
- Verify high-impact facts directly with the issuer or source system.
- Do not treat missing file signals as proof of authenticity.
If you believe you found a security issue, email security@ocolta.com with a clear reproduction. Do not include real applicant documents.
Start with evidence
Start with the workflow that keeps the file on-device.
Run a private, browser-based integrity scan. Your file never leaves your device.
Scan a document