Trust center · Private preview

What protects the work—and what still requires an agreement.

Source-linked disclosures for security, privacy, AI providers, data lifecycle, service dependencies, and current operating boundaries.
Service stagePrivate previewControls and terms continue to develop.
Last reviewedSeptember 4, 2026Provider policies can change independently.
OperatorEGON HOLDINGS LLCOwner and operator of EX MULTIS™.

Start with the record

One place to inspect the current commitments.

Each page below addresses a different part of the trust record. This center joins them without turning vendor claims into EX MULTIS certifications.

Current operating controls

What the product enforces today.

Transport

HTTPS at the public boundary

EX MULTIS is served over HTTPS. Selected AI-provider connections are made by the application’s servers, not directly from the user’s browser.

Credentials

Provider secrets stay server-side

AI-provider and privileged service credentials are intended to remain in server environment settings and are not placed in public browser code.

Access

Authenticated workspace boundaries

Authentication, workspace membership or project ownership checks, and database row-access policies restrict private records to authorized accounts.

Traceability

Review records stay inspectable

Provider responses, synthesis, citations, disagreement, and selected decision records are stored as distinct records where the workflow supports them.

Deletion

Project deletion is available

Users can delete projects. Related database records use connected deletion rules where implemented. Account-level or verified privacy requests are handled through support.

Authorized access

Operational access is limited

Authorized operators may access information when needed to support, secure, troubleshoot, or administer the service. EX MULTIS does not publish a broader employee-access claim.

Data lifecycle

Where information goes and how long it stays.

EX MULTIS does not currently promise one universal retention period. Duration depends on the record, service need, provider, plan, legal obligation, and any written customer agreement.

Account and workspace recordsSupabase authentication and database

Used to authenticate users, assign workspace access, and operate the account. Retained while needed to provide the account and for legitimate legal, billing, security, or dispute purposes. Verified access, correction, or deletion requests may be sent to support.

Projects, reviews, and conversationsSupabase database

Used to preserve the working record and produce reports. Project deletion removes the project and connected database records where deletion rules apply. No fixed automated expiration or universal backup-erasure deadline is promised during private preview.

Uploaded filesPrivate Supabase Storage plus file metadata

Used only for the workflow the user requests. Files use access-controlled storage and short-lived signed download links. Storage objects and database backups are separate systems, so deletion and backup behavior are not identical.

Payment and billing recordsStripe plus EX MULTIS billing records

Stripe handles checkout and payment-card processing. EX MULTIS stores identifiers, subscription or entitlement state, and billing events needed to administer service, accounting, fraud prevention, disputes, and legal obligations—not full payment-card numbers.

Operational and security recordsApplication and hosting services

Used to operate, secure, diagnose, and prevent abuse. Log availability and retention depend on the applicable service and plan. EX MULTIS does not publish a single fixed log-retention schedule during private preview.

AI-provider contentThe provider selected for the route

Only the material needed for the requested route is sent. Provider training, temporary retention, and stricter data-control eligibility are listed on the AI provider data practices page.

Service dependencies

Providers that may handle service data.

The exact providers involved depend on the feature a user selects. The links below lead to the vendors’ current official materials; their policies control if this summary differs.

EX MULTIS service dependencies, roles, data, boundaries, and official sources
Provider and roleData involvedEX MULTIS boundaryOfficial sources
VercelWeb hosting and application runtimeApplication requests, content in transit, and operational metadata.Log retention and contractual controls depend on the active plan. Vendor controls do not certify EX MULTIS.
SupabaseAuthentication, database, and private file storageAccount identifiers, workspaces, projects, review records, and uploaded files.Project region and backup availability are provider- and plan-specific. Storage objects are separate from database backups.
StripeCheckout, subscriptions, and billing portalPayment and billing information needed to complete and administer a purchase.Stripe processes payment-card data. EX MULTIS stores service identifiers and billing records, not full card numbers.
AI model providersSelected model review, research, and extractionThe prompt, file content, or prior context needed for the selected route.Training and retention vary by provider, endpoint, account, and feature. Zero Data Retention is represented as active only after confirmation.
GitHubRepository authorization and source intake for code workflowsRepository identity and source selected by an authorized user.Feature-specific: GitHub data is not required for ordinary review workflows.
Render and E2BFeature-specific analysis runner and isolated code executionSource or job material needed for a user-invoked code or assurance workflow.Not used for ordinary review workflows. Execution environments are temporary; EX MULTIS does not promise a customer-selected execution region during preview.

Written confirmation required

Do not assume a preview feature is an institutional commitment.

The following require review and a written agreement or account-level confirmation before EX MULTIS represents them as active.

  • Use with regulated, student, patient, employee, highly sensitive, or other institutionally restricted information
  • A guaranteed data-processing or storage region
  • Zero Data Retention or another provider-specific retention configuration
  • A fixed security-incident notification period
  • Uptime, response-time, recovery-time, recovery-point, or support service levels
  • A data processing addendum, business associate agreement, or institution-specific terms

Incidents

Notification and response

EX MULTIS will investigate suspected security incidents and notify affected customers when required by law or a written agreement. The private preview does not include a universal notification deadline, uptime commitment, or published recovery objective.

Vulnerabilities

Report a security issue

Send a clear description, affected URL or feature, and safe reproduction steps to support@exmultis.com. Do not access other users’ information, disrupt service, or include secrets in the first message.

Read the reporting guidance →

Questions about data handling, provider routing, institutional review, or contractual safeguards may be sent to support@exmultis.com. Provider terms and product features can change; the review date at the top records when this page was last checked.