Private file storage
Implemented
How it is enforced
Permit source files and exports use non-public storage buckets with organization-aware object policies.
Security · document handling
The question your team must answer
See how a permit moves through private storage, bounded AI processing, organisation-scoped review and a human-approved result — and which choices still need your agreement.
01
Files, records and review actions are kept inside explicit access and decision boundaries.
Implemented
Permit source files and exports use non-public storage buckets with organization-aware object policies.
Implemented
Permit tables use organization membership policies to restrict record access.
Implemented
Extracted fields can retain page, snippet, confidence and review information where available.
Implemented
Workspace administrators can delete a permit; source files, exports and extracted payloads are purged, with failed storage cleanup retried by the worker.
02
Follow the current permit workflow from upload to reviewed result. OpenAI appears exactly where the document crosses an external processing boundary.
A PDF or supported image is placed in private permit storage under its organization and document path.
The complete PDF or image is sent to the configured OpenAI Responses API model for extraction.
The returned JSON is schema-checked, validated and stored with the organization-scoped permit record.
A user reviews sources, uncertainty and corrections before approving an export.
03 · indexed trust dossier
Each section separates the control visible in the current product from its operational boundary. This is the detail an IT, privacy or procurement review can inspect.
Application accounts and sessions are handled through Supabase Auth.
Permit tables use organization membership policies to restrict record access.
Permit source files and exports use non-public storage buckets with organization-aware object policies.
Permit documents, extraction jobs, review events and exports are separate from emissions records.
A PDF or supported image is placed in private permit storage under its organization and document path.
The complete PDF or image is sent to the configured OpenAI Responses API model for extraction.
The returned JSON is schema-checked, validated and stored with the organization-scoped permit record.
Permit requests are sent with the OpenAI API parameter store: false. This prevents application-requested response storage, but does not by itself define every provider-side abuse-monitoring or retention condition.
LogisticsAI does not use customer permits to train a model of its own. Applicable OpenAI data-use terms and account controls must be confirmed for the production agreement.
Extracted fields can retain page, snippet, confidence and review information where available.
A user reviews sources, uncertainty and corrections before approving an export.
Workspace administrators can explicitly delete a permit. Its private source file and generated exports are then purged.
Deletion removes extracted fields and provider payloads. A content-free tombstone and sanitized audit timeline remain as a deletion record.
Backups, security logs and provider-side records can follow separate operational or contractual schedules.
Failed private-storage cleanup is kept inaccessible and retried by the background worker. Backups remain subject to infrastructure schedules.
Next · your requirements
We can map each question to the workflow, data path, provider and responsibility that it affects. A meeting is optional.