Trust & Security

Your data stays yours

Surface uses AI to power design generation, but Surface does not use your designs, logos, or brand assets to train its own models. Here’s how we protect your work and describe provider handling accurately.

AI Governance

Surface integrates multiple AI providers for texture generation. Every integration is reviewed against a no-training policy:

Customer inputs are sent only to the provider selected for an active generation request
Surface does not use customer content to train or fine-tune its own models
Surface does not include prompts, reference bytes, or raw provider responses in application telemetry
Business API terms generally prohibit model training on customer content, but limited security and abuse-monitoring retention may apply as described below

Data Protection

Your design files, brand assets, and account data are protected with industry-standard security:

Encryption in transit (TLS) and provider-managed encryption at rest
Role-based access control with organization-level permissions
Private customer storage delivered through short-lived links after user and organization authorization
Authentication via secure token verification on every API request
Rate limiting, audit logging, and timeout protections on sensitive endpoints

Data Deletion

We support verified data deletion requests under applicable privacy laws and customer agreements.

Request deletion of all personal data and design files at any time
Verified deletion removes active account, database, and stored file records; organization owners may also delete organization data
Limited financial, security, or legal records may be retained in a minimized form where required
Database recovery points roll out of a seven-day window; deleted object generations age out of the independent 30-day backup window
Hashed deletion tombstones are replayed during recovery to avoid intentionally restoring deleted accounts, organizations, or files

To submit a deletion request, contact us at support@surface3d.ai.

Transparency

Every AI generation is logged with the model used and credit cost
You choose which AI model to use for each generation
Credit costs are displayed before generation and itemized in transaction history
AI governance policies are reviewed quarterly and updated when providers or regulations change

Business Continuity

Surface is built on a distributed architecture designed for resilience:

Application deployed across a global CDN with instant rollback capability
Version-controlled application code, database migrations, and documented rollback procedures
Multiple AI providers can be selected if a provider is unavailable
Automatic daily database backups are retained for seven days; point-in-time database recovery is not currently enabled
All Supabase Storage buckets and identified legacy Firebase files are copied weekly on Sunday to a separate private Google Cloud project with versioning and a 30-day retention policy
Files created and deleted between weekly object-backup runs might not reach the independent recovery copy
Backup runs generate SHA-256 manifests, verify recovery samples, and alert on explicit failures or missed runs

Disaster Recovery

Recovery procedures prioritize identity, database access, customer files, and the application deployment. Current operating targets are planning goals, not a contractual SLA:

Application releases can be rolled back through the hosting platform and rebuilt from version-controlled source
Database and object backups are implemented; achieved end-to-end recovery objectives will be published only after a complete isolated restore exercise is evidenced
Documented procedures for every failure scenario including security incidents
Enterprise RTO/RPO commitments are available only in a separately executed agreement

Third-Party Sub-processors

Surface3D shares data with the following third-party services to operate the platform. AI providers receive content only for requested generations and may retain limited data under their published security and abuse-monitoring policies.

ProviderPurposeData Shared
Google Cloud (Firebase / Cloud Storage / Gemini API)Authentication, legacy file storage, independent backups, AI generationAccount records, versioned file backups, hashed deletion tombstones, legacy files, AI prompts, reference images, logos; limited Gemini abuse-monitoring retention may apply unless ZDR is approved
SupabasePrimary database, file storage, and database recovery pointsUser profiles, organization data, projects, files, credit transactions, activity logs
OpenAIAI image generation and reference analysisAI prompts, reference images, logos; default abuse-monitoring retention may be up to 30 days
ReplicateAI image generation (Flux, Recraft)AI prompts, reference images, logos; API inputs, outputs, and logs are removed after about one hour by default
StripePayment processingName, email, billing address, payment details
VercelApplication hostingWeb traffic, IP addresses, request metadata
ResendTransactional emailName, email address

Documentation

Questions?

Reach out during your security review process and we’ll get you what you need.

support@surface3d.ai
Independent SOC 2 examination not yet completed