Security and data

Where your documents run, and who can touch them

"Your data stays local" means it stays in your environment and under your control. This page says what that covers, how the deployment is chosen for each workflow, and what we put in writing before any document is shared.

Three deployment options

Option 1

Your servers

The extraction stack runs on hardware you own or lease. Documents, models and output stay inside your network. We work through the access you grant and hold no copy.

Chosen when documents cannot leave the building, or volume is high enough that owned hardware costs less.

Option 2

A private cloud you control

The same stack in a cloud account or tenancy that is yours: your contract with the provider, your keys, your region, your logs.

Chosen when you have no suitable hardware, or volume is too uneven to justify buying it.

Option 3

Hybrid

Repeatable volume work runs in your environment. A small share of hard pages may go to a hosted model, only for document types you have approved and only when it costs less.

Chosen when a few exceptions would otherwise force you to overbuy hardware.

How one is chosen

Per workflow, not per company. For each document type we ask three questions with your compliance owner: may these pages leave your network at all, what does each option cost at your real volume, and what accuracy does the workflow need.

The pilot measures the answers on your own documents. The decision and its reasons are written into the pilot report, so an auditor can see why each workflow runs where it does.

Owned hardware is not always the cheapest answer. At low volume a hosted open-weight model often costs less, and when it does we say so.

Data retention

In a deployment in your environment, retention is your policy. Documents and output never reach infrastructure we operate, so there is nothing for us to keep or delete.

When a pilot or a managed batch runs on infrastructure we operate, the retention period is a term of the data processing agreement, fixed before the first document arrives. Our default proposal is the shortest one that works: source documents and output are deleted once you confirm delivery, unless you ask us to hold them longer for reprocessing.

Data processing agreement

Available for every engagement, and signed before any document that contains personal data is shared, pilots included. You remain the data controller; Akora SIA acts as processor and works only on your documented instructions. If your organization has its own DPA template, we work from yours.

Sub-processors

For document processing in your environment: none. No third party receives your documents.

If a workflow uses a private cloud provider or a hosted model for exceptions, each provider is named in the DPA before it is used, and you can refuse any of them.

This website is separate from client work. It uses:

  • Hostinger: hosts this website
  • Ahrefs Web Analytics: cookieless page statistics
  • Web3Forms and hCaptcha: deliver and protect the contact form
  • Calendly and Google Meet: book and hold the discovery call

What the site itself collects is covered in the privacy policy.

Model training

We never train or fine-tune models on customer data. Your documents and the data extracted from them are used to deliver your output and for nothing else.

If an engagement includes adapting a model to your documents, that is agreed in writing first and runs inside your environment.

What this is not

It is not a geography promise. We do not sell residency in the EU or any other region as a guarantee. The promise is control: the processing runs where you decide, on infrastructure you govern. If your rules require a specific country or region, you pick the servers or the cloud region, and the deployment follows.

Who is accountable

Akora SIA, registration number 40203566478, Upes 11, LV-2008, Latvia. Questions about security or data handling go to hola@aekora.com and are answered by a founder.

Bring your compliance owner to the call.

The deployment decision is theirs as much as yours. We would rather hear the constraints first.

Book a discovery call

What happens on the discovery call

15 minutes · video call · with Daniel Arevalo, CPO

  1. Step 1

    You describe the documents

    Types, rough monthly volume, and where the data is allowed to be. Nothing confidential is shared on this call.

  2. Step 2

    We ask where the output goes

    The ERP, database or API the data has to land in, and any compliance limits we need to design around.

  3. Step 3

    We tell you if it is a fit

    Including when it is not: if a hosted service would cost less at your volume, we say so.

  4. Step 4

    You get the next step in writing

    Usually a pilot scope on about 100 of your documents. A data processing agreement is signed before any document is sent.

How documents are handled once work starts: Security and data.