FliktTrust & Security

Trust & Security

Last Updated: September 8, 2026

Your plans are your most sensitive project data. We built Flikt.AI with that in mind.

Every document you upload is encrypted in transit and at rest, isolated to your account, and never shared with other users or third parties. Your files are processed by AI for conflict detection only—they are not used to train AI models, not stored beyond your engagement, and not accessible to anyone outside your authorized team.

Encrypted Everywhere

TLS 1.2/1.3 in transit, AES-256 at rest

Tenant Isolation

Your data is never visible to other users

AWS Infrastructure

Hosted entirely on Amazon Web Services (US)

No AI Training

Your documents are never used to train models

1. How Your Documents Are Protected

Upload Security

When you upload construction documents to Flikt.AI, your files travel directly from your browser to our secure cloud storage using pre-authenticated, time-limited upload URLs. Files never pass through an intermediate server—they go straight to encrypted storage. Each upload URL expires within 15 minutes and is scoped exclusively to your account and project.

Encryption Standards

All data transmitted between your browser and Flikt.AI is encrypted using TLS 1.2 or TLS 1.3 with strong cipher suites (HIGH grade, no legacy protocols). At rest, your documents are encrypted using AES-256 server-side encryption, the same standard used by financial institutions and government agencies worldwide.

Account-Level Isolation

Every file you upload is stored in a unique, account-scoped location that is inaccessible to any other user on the platform. Your projects, documents, and analysis results are isolated at the application level, the database level, and the storage level. There is no shared access between customer accounts.

2. AI Processing & Data Usage

How AI Analyzes Your Plans

Flikt.AI uses advanced AI vision models to extract building elements from your plan sheets and detect conflicts across disciplines. Your documents are sent to the AI provider (Anthropic) via their commercial API exclusively for the purpose of analyzing your project. The AI processes each page, returns structured results, and the interaction ends.

No Model Training on Your Data

Your uploaded documents are never used to train, fine-tune, or improve third-party AI models. Our AI provider (Anthropic) explicitly does not use commercial API inputs for model training purposes. Your plans remain your intellectual property at all times.

Zero Data Retention by AI Provider

Flikt.AI holds a zero-data-retention agreement with our AI provider (Anthropic), applied at the account level across all of our API traffic. Your document data is not retained beyond the duration of each API call: once the analysis response is returned, your document content is not stored on the AI provider’s systems. This is a contractual commitment, not only a configuration setting. Flikt.AI retains your analysis results only for the duration of your engagement, after which you may request deletion.

3. Infrastructure & Hosting

Amazon Web Services (AWS)

Flikt.AI’s entire infrastructure is hosted on Amazon Web Services in the United States (US-East-1 region). AWS maintains industry-leading security certifications including SOC 1/2/3, ISO 27001, FedRAMP, and PCI DSS Level 1. Our infrastructure includes dedicated compute instances, managed databases with automated backups, and encrypted object storage.

Network Security

Our production environment uses firewall rules that restrict access to only necessary ports and protocols. Administrative access requires SSH key authentication—no password-based access is permitted. All API endpoints are protected by rate limiting to prevent abuse, and our web traffic is routed through Cloudflare for additional DDoS protection and traffic filtering.

4. Authentication & Access Control

User authentication is managed by Clerk, an enterprise-grade identity platform. All user sessions are secured with cryptographically signed JSON Web Tokens (JWT) using RS256 signatures. Every API request is authenticated—there are no unauthenticated endpoints that access customer data.

Shared report links use unique, cryptographically random tokens with automatic expiration. Report owners can revoke shared access at any time with a single click.

5. Payment Security

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. Flikt.AI never stores, processes, or transmits credit card numbers or bank account details. Payment information is entered directly on Stripe-hosted pages and never touches Flikt.AI servers. We support ACH direct debit for enterprise customers who prefer bank-level payment security.

6. Data Retention & Deletion

You retain full ownership of all documents you upload to Flikt.AI. Upon request, we will permanently delete all of your uploaded documents, analysis results, and account data. Deletion requests can be submitted to [email protected] and will be processed within 30 days in accordance with applicable data protection laws.

We do not sell, rent, or share your documents or personal information with third parties for marketing or any other purpose unrelated to providing our service.

7. Compliance & Legal

Flikt.AI is committed to compliance with applicable data protection regulations. Our practices align with the requirements of the California Consumer Privacy Act (CCPA), the Florida Information Protection Act (FIPA), and the General Data Protection Regulation (GDPR) for any EU-based users. For details, see our Privacy Policy.

Our Terms of Service include mutual confidentiality obligations, intellectual property protections, and liability provisions appropriate for enterprise engagements. A Master Service Agreement (MSA) is available for institutional clients requiring additional contractual protections.

8. Incident Response

Flikt.AI maintains monitoring and alerting systems to detect and respond to security events. In the unlikely event of a data breach affecting your information, we will notify affected customers promptly in accordance with applicable law and our contractual obligations. Our error tracking and health monitoring systems provide real-time visibility into platform status.

9. Frequently Asked Questions

Can other Flikt.AI customers see my plans?

No. Every account is fully isolated. Your documents, projects, and analysis results are accessible only to authenticated users on your account. There is no cross-tenant data access of any kind.

Does Flikt.AI employees have access to my documents?

Access to customer documents is restricted to authorized personnel on a need-to-access basis for the sole purpose of providing technical support or troubleshooting service issues. We do not browse, review, or analyze customer documents for any other purpose.

Where are my files physically stored?

All files are stored in Amazon S3 in the US-East-1 (Northern Virginia) AWS region, encrypted at rest using AES-256. AWS data centers maintain physical security controls including 24/7 monitoring, biometric access, and environmental protections.

Can I get my data deleted after a project is complete?

Yes. Contact [email protected] at any time to request deletion of your uploaded documents and analysis data. We will confirm deletion in writing within 30 days.

Do you have SOC 2 certification?

Flikt.AI is currently pursuing SOC 2 Type II certification. Our infrastructure provider (AWS) maintains SOC 1/2/3 compliance, and our application architecture follows security best practices aligned with SOC 2 Trust Service Criteria. We are happy to discuss our security controls in detail with your compliance team.

Can we sign an NDA or Data Processing Agreement?

Absolutely. We provide a Master Service Agreement (MSA) with built-in confidentiality provisions for all enterprise engagements. We can also execute standalone NDAs or Data Processing Agreements upon request. Contact [email protected] to initiate.

What happens if I share a report with a third party?

Shared report links provide read-only access to conflict detection results only—not to your original uploaded documents. Links expire automatically and can be revoked at any time. The shared view does not include access to your account, other projects, or any uploaded files.

Have additional security questions?

We’re happy to walk through our security practices with your IT or compliance team.

Flikt.AI — Plan Conflict Detection