Security and data handling

Fjord is built with security at its heart. Your client work stays yours: never used for training, never retained at the model layer, and always in the region you choose.

Our commitments

Client data is never used to train models.
Nothing you upload trains any model, ours or a provider's. This is contractual, not a setting.
No logging or retention at the model layer.
Our inference routing is configured with prompt logging and data retention disabled, so your content is not held between requests.
Regional data residency.
Choose the region your data lives in, including the United States. Data stays in the region you select.
Logical isolation between customers.
Each customer's data is isolated at the storage layer, with no shared retrieval across customers.
Encryption at rest and in transit.
AES 256 at rest, TLS 1.2 or above in transit.
Role based access control.
Firm administrators control who can see which workspaces and which uploaded material. Access by our personnel is least privilege, logged, and reviewed.
Bring your own model keys.
If your client agreements require your own provider contract, use your own credentials. Your traffic then runs entirely under your agreement, and that provider's terms govern it directly.
Private cloud deployment.
Available from 30 seats. Fjord runs inside your own cloud tenancy, and no data leaves your environment.
Breach notification within 72 hours.
If we become aware of a breach affecting your data, you hear from us within 72 hours with what we know, what is affected, and what we are doing.

Retention and deletion

Source files and generated decks
Held in your workspace until you delete them.
Deletion requests
Actioned within 14 days of a written request, removing the data from active storage and backups.
Copies outside your workspace
None. Client content is not retained for product improvement, benchmarking or evaluation.
On termination
Export everything for 90 days, after which it is deleted.

Models and subprocessors

Fjord uses a small number of infrastructure and model providers, all under agreements that prohibit training on customer content and disable logging and retention.

We provide the current subprocessor list on request, under NDA, along with the underlying commitments. Firms deploying to private cloud, or running their own model credentials, control this entirely.

Contact

Security questions go to security@fjordresearch.ai. We respond within two working days.