Security Policy
Effective August 11, 2026 · PEFG, PLLC (Illinois)
This page describes the technical and operational controls protecting the documents and information you submit to this Service. Uploaded documents are frequently confidential — drawings, studies, procedures, and survey data an organization hasn't yet covered under an NDA with us — and this Service is built around that fact.
Malware scanning before anything else touches your file
Every uploaded file is scanned by a malware scanner running inside our own infrastructure before it is persisted to storage or read by anything downstream. We do not send uploaded files to a third-party scanning API — a confidential document you haven't yet covered under an NDA with us shouldn't go to a fourth party just to get scanned. A file that fails the scan is rejected outright and never stored.
Encryption
- All traffic to and from this Service is encrypted in transit (TLS).
- Uploaded documents and generated reports are stored in a private object storage bucket with server-side encryption at rest. Nothing is ever served from a public bucket or URL.
- Database connections are encrypted in transit.
Access controls
- The admin review queue is authenticated and restricted to an explicit allowlist of owner email addresses — no general employee or contractor access exists beyond that allowlist.
- The customer portal only ever shows a signed-in user their own orders, uploads, and reports.
- Report and document downloads are served through short-lived signed URLs, not permanent public links.
- There is no password to leak: sign-in uses a one-time email link, not a stored password, for both customer and admin access.
AI processing
Document review is performed server-side via the Anthropic Claude API. Your document is never sent to the browser, never processed client-side, and the API credentials used to call it are never exposed outside our server environment.
Reduced attack surface by design
This Service has no phone line, no live chat, and no booking calendar — every one of those is a common social-engineering vector, and none of them exist here. Support is email only.
Retention
Uploaded documents are deleted automatically 30 days after your job completes, and sooner on request — see the Data Retention Policy. A shorter retention window means less data to protect in the first place.
Incident notification
If we become aware of a security incident that resulted in unauthorized access to your documents or personal information, we will notify you at the email address on file without undue delay, and in any case within the timeframe required by applicable law.
Reporting a vulnerability
If you believe you've found a security issue with this Service, please report it to support@pefgconsulting.com before disclosing it publicly. We'll acknowledge reports promptly.