Security & Privacy

Your data belongs to you — and only you. Here is how we enforce that technically.

Encryption at Rest

All content, captures, and personal data are encrypted using AES-256-GCM with per-user Data Encryption Keys (DEKs). Your content is never stored in plain text at any layer.

Envelope Encryption

Each user has their own encryption key. User keys are encrypted with a master key that is managed separately from the database. This means that even in the event of a database breach, your content cannot be read without your key.

Crypto Shredding

When you delete your account, your encryption key is destroyed. Without the key, your data is mathematically unrecoverable — not just marked for deletion, but permanently inaccessible. This is crypto shredding, and it is the highest standard of data deletion available.

Bring Your Own Key (BYOK)

Enterprise users can supply their own master encryption key. Your key, your data, your control. Golden Tech Solutions never has access to a BYOK user’s encryption key.

API Key Security

All AI provider API keys (OpenAI, Anthropic, Google) are encrypted at rest with per-user envelope encryption. They are never stored in plain text, never appear in logs, and never transmitted beyond the immediate API call they are used for.

Authentication

Infrastructure

Data Ownership

Your content is yours. GoldenIris does not use your content to train AI models. Your captures, drafts, and published content are never shared with third parties. You can export everything at any time from Settings → Data → Export.

For questions about data handling, encryption specifics, or compliance requirements, contact [email protected].

GoldenIris is a product of Golden Tech Solutions LLC. All data processing is governed by the Golden Tech Solutions Privacy Policy and Terms of Service.