Trust, security & procurement

How we handle your data.

Archivers.ai sits in front of your repository or collections system, and works alongside it — today, that system stays authoritative.

Works with your system of record — yours stays authoritative

UK/EU-first hosting and AI processing

DPA published in full, with sub-processors

Human review before anything publishes

Procurement pack

Everything your IG team asks for.

Two documents are published. The rest we send on request, usually the same day.

Where your data lives

Storage and compute

Application compute runs on Vercel’s London region (lhr1). Customer data is stored on Neon Postgres in AWS’s London region (eu-west-2).

Audio and video pass through a Google Cloud Storage EU multi-region bucket for processing, on a short, fixed object lifecycle. Data is encrypted in transit and at rest.

Where AI processing happens

Optical character recognition, image and object description, and audio transcription run on a European model provider based in France. Video analysis runs on Google Vertex AI in EU regions.

Description, grounding and reasoning route through Google Vertex AI, restricted to EU regions, using workload identity federation rather than long-lived cloud keys. Error monitoring is EU-resident and captures no personal data by default.

For GDPR-sensitive collections we can run an EU-only processing mode. If your team needs a specific residency guarantee, raise it and we will confirm what we can commit to in writing.

What we do not claim

We do not claim your data never leaves the UK. Audio and video are processed in the EU, and several infrastructure providers are US-headquartered companies.

Where a US entity is involved, Standard Contractual Clauses and the UK International Data Transfer Addendum are the transfer mechanism. The security brief sets out which supplier sits where.

Who owns it, and how it leaves

Ownership

You do. Collections, source files, draft and reviewed metadata, exports and audit history belong to the customer. We act as a processor and claim no ownership.

Model training

Customer collection data is not used to train foundation AI models; we follow vendor no-training commitments under paid business-tier API terms. Archivers.ai has no training pipeline of its own.

Aggregated operational metrics — processing volumes, error rates, system health — are used to improve the platform. No metadata, file content or imagery is included.

Deletion

You can delete data at any time. Deletion takes effect promptly in the working copy, and in backups within a defined retention window, after which it is unrecoverable.

Depositor records have their own GDPR tooling: a per-depositor export, an anonymise action, and a guarded merge for duplicates.

Exit

Because everything exports in open, standards-based formats, there is no lock-in at the data layer.

On exit we export a final copy, delete working data, and confirm deletion in writing.

Which formats can we take with us?
  • EAD3 finding aids (XML)
  • BagIt packages with PREMIS provenance
  • Dublin Core
  • Import CSV for AtoM, ArchivesSpace and Archivematica
  • Spectrum-mapped records for museum workflows
  • JSON and Markdown for publishing pipelines

Export formats · Standards

The review gate

Nothing publishes unreviewed

Every AI-generated description is a draft until an archivist signs it off. The platform shows the source evidence behind each suggestion, flags fields with none, and scores transcripts word by word.

For institutional plans we agree review policy during onboarding — mandatory review for a whole fonds, sampling for low-risk material, or two-tier review for retroconversion.

Evidence and warnings

Each AI-assisted field cites the evidence it was drawn from, or states that it has none. Transcripts carry per-word OCR confidence, summarised as high, medium or low, and field warnings mark where the transcript and the image disagree. All of it sits beside the suggestion in the review screen.

Flags are advisory. No field is ever auto-approved on the strength of a high score.

Audit trail

We record provenance for AI-assisted fields including model, timestamp and review state, alongside who created and reviewed each field, the raw suggestion, any override, and export history.

Provenance travels with the record — recorded as PREMIS events inside a BagIt package, so downstream systems can see how a record was made and who approved it.

Security and access

Account controls

Two-factor authentication is in the product. An authenticator app is the default, because the secret is encrypted and verification never leaves the EU.

SMS is available for organisations that need it, delivered by a US-based provider — so an authenticator app is the better choice where EU residency of every step matters.

The full control list
  • Organisation-level 2FA enforcement, with admin-mediated reset
  • Organisation workspaces with per-user roles
  • Passwords hashed with bcrypt; session tokens stored as SHA-256 hashes
  • Security headers (HSTS, CSP) on every response
  • Encryption in transit and at rest
  • Production access restricted to named staff, and logged
  • Automated secret-scanning on every code change before it ships

Two honest caveats

Rate limiting is currently per-server rather than a distributed cross-server limiter. Blob-stored files are protected by the app’s own access gating rather than URL secrecy alone.

Neither is unusual at this stage, and both are on the roadmap to harden. Single sign-on is coming soon; IP restrictions and specific authentication policies are discussed at onboarding.

Accessibility

WCAG 2.2 Level AA is our working target for the platform and for public access products — not a conformance claim. Where a component falls short we say so and share the gap.

Sub-processors

We rely on a small, declared set: cloud infrastructure, AI model providers, and transactional email and analytics.

The current list, with purposes, regions and data scope, is published in the Data Processing Agreement. We notify customers of material changes before they take effect.

Confidence detail in Archivers.ai: transcript quality scored High at an average of 0.93, forty-nine flagged terms, and a field warning where the transcript read the surname as Collins while the image shows Collis, scored 0.78 and left for a human to settle

Evidence and warnings sit beside the suggestion, in the review screen itself.

The export dialog in Archivers.ai with the output format picker open, offering standards-based archival formats for a selected set of catalogue records

Exit is a button, not a negotiation — the same export dialog your team uses daily.

Procurement-ready from day one.

Start free, or tell us which documents your process needs and we will send them across.