Start with the record
One place to inspect the current commitments.
Each page below addresses a different part of the trust record. This center joins them without turning vendor claims into EX MULTIS certifications.
Privacy
Information categories, purposes, choices, and requests.
Read the privacy policyAI provider data
Provider-by-provider training and retention positions.
Review AI data practicesSecurity
Transport, credentials, access boundaries, and reporting.
See the security posturePreview boundaries
What the private preview includes—and what it does not promise.
Review preview expectationsReview method
Routing, independent analysis, synthesis, and human judgment.
Inspect the review systemPublic sample
A source-linked example of the report a user receives.
Open the sample reportCurrent operating controls
What the product enforces today.
HTTPS at the public boundary
EX MULTIS is served over HTTPS. Selected AI-provider connections are made by the application’s servers, not directly from the user’s browser.
Provider secrets stay server-side
AI-provider and privileged service credentials are intended to remain in server environment settings and are not placed in public browser code.
Authenticated workspace boundaries
Authentication, workspace membership or project ownership checks, and database row-access policies restrict private records to authorized accounts.
Review records stay inspectable
Provider responses, synthesis, citations, disagreement, and selected decision records are stored as distinct records where the workflow supports them.
Project deletion is available
Users can delete projects. Related database records use connected deletion rules where implemented. Account-level or verified privacy requests are handled through support.
Operational access is limited
Authorized operators may access information when needed to support, secure, troubleshoot, or administer the service. EX MULTIS does not publish a broader employee-access claim.
Data lifecycle
Where information goes and how long it stays.
EX MULTIS does not currently promise one universal retention period. Duration depends on the record, service need, provider, plan, legal obligation, and any written customer agreement.
Used to authenticate users, assign workspace access, and operate the account. Retained while needed to provide the account and for legitimate legal, billing, security, or dispute purposes. Verified access, correction, or deletion requests may be sent to support.
Used to preserve the working record and produce reports. Project deletion removes the project and connected database records where deletion rules apply. No fixed automated expiration or universal backup-erasure deadline is promised during private preview.
Used only for the workflow the user requests. Files use access-controlled storage and short-lived signed download links. Storage objects and database backups are separate systems, so deletion and backup behavior are not identical.
Stripe handles checkout and payment-card processing. EX MULTIS stores identifiers, subscription or entitlement state, and billing events needed to administer service, accounting, fraud prevention, disputes, and legal obligations—not full payment-card numbers.
Used to operate, secure, diagnose, and prevent abuse. Log availability and retention depend on the applicable service and plan. EX MULTIS does not publish a single fixed log-retention schedule during private preview.
Only the material needed for the requested route is sent. Provider training, temporary retention, and stricter data-control eligibility are listed on the AI provider data practices page.
Service dependencies
Providers that may handle service data.
The exact providers involved depend on the feature a user selects. The links below lead to the vendors’ current official materials; their policies control if this summary differs.
| Provider and role | Data involved | EX MULTIS boundary | Official sources |
|---|---|---|---|
| VercelWeb hosting and application runtime | Application requests, content in transit, and operational metadata. | Log retention and contractual controls depend on the active plan. Vendor controls do not certify EX MULTIS. | |
| SupabaseAuthentication, database, and private file storage | Account identifiers, workspaces, projects, review records, and uploaded files. | Project region and backup availability are provider- and plan-specific. Storage objects are separate from database backups. | |
| StripeCheckout, subscriptions, and billing portal | Payment and billing information needed to complete and administer a purchase. | Stripe processes payment-card data. EX MULTIS stores service identifiers and billing records, not full card numbers. | |
| AI model providersSelected model review, research, and extraction | The prompt, file content, or prior context needed for the selected route. | Training and retention vary by provider, endpoint, account, and feature. Zero Data Retention is represented as active only after confirmation. | |
| GitHubRepository authorization and source intake for code workflows | Repository identity and source selected by an authorized user. | Feature-specific: GitHub data is not required for ordinary review workflows. | |
| Render and E2BFeature-specific analysis runner and isolated code execution | Source or job material needed for a user-invoked code or assurance workflow. | Not used for ordinary review workflows. Execution environments are temporary; EX MULTIS does not promise a customer-selected execution region during preview. |
Written confirmation required
Do not assume a preview feature is an institutional commitment.
The following require review and a written agreement or account-level confirmation before EX MULTIS represents them as active.
- Use with regulated, student, patient, employee, highly sensitive, or other institutionally restricted information
- A guaranteed data-processing or storage region
- Zero Data Retention or another provider-specific retention configuration
- A fixed security-incident notification period
- Uptime, response-time, recovery-time, recovery-point, or support service levels
- A data processing addendum, business associate agreement, or institution-specific terms
Incidents
Notification and response
EX MULTIS will investigate suspected security incidents and notify affected customers when required by law or a written agreement. The private preview does not include a universal notification deadline, uptime commitment, or published recovery objective.
Vulnerabilities
Report a security issue
Send a clear description, affected URL or feature, and safe reproduction steps to support@exmultis.com. Do not access other users’ information, disrupt service, or include secrets in the first message.
Read the reporting guidance →Questions about data handling, provider routing, institutional review, or contractual safeguards may be sent to support@exmultis.com. Provider terms and product features can change; the review date at the top records when this page was last checked.
