Security & data

Where your client's data actually goes when you run a case review, and what's kept afterwards.

Processing

Where the data is processed

Bank statement and income document data is processed using Anthropic's Claude, via their commercial API. Under Anthropic's Commercial Terms of Service, this data is contractually excluded from being used to train their models, and is automatically deleted from their systems within 30 days. A Data Processing Addendum covering this processing is already in place, and the international transfer is covered by Standard Contractual Clauses and the UK International Data Transfer Addendum — the standard UK GDPR safeguard for this kind of transfer.

This describes Anthropic's standard commercial terms for the Claude API, verified against their published Commercial Terms of Service and Privacy Center.

Hosting & encryption

Where it runs, and how it's protected in transit and at rest

Scrivenza runs entirely on Microsoft Azure, hosted in the UK South region — your data doesn't leave UK/EU infrastructure except for the Claude API processing described above. Every connection to the site and between its own services is encrypted in transit (HTTPS enforced, HSTS enabled), and data at rest is encrypted using Azure's platform-level encryption across app hosting, database and secrets storage.

Access

Who can get to what

Trial and Portal accounts sign in via a one-time login link sent to the account's own email — there's no password to guess or leak. The public API authenticates every request against a scoped API key, unique per subscriber. Internal admin access is separately gated behind Microsoft Entra sign-in, restricted to the founder account.

Breach notification

If something ever goes wrong

As a UK GDPR data controller, Scrivenza is legally required to notify the ICO within 72 hours of becoming aware of a personal data breach where feasible, and to notify affected individuals directly where the breach is likely to result in a high risk to them — the standard both hold Scrivenza to, not a lesser one.

Retention

What Scrivenza itself keeps

For the complete picture of what's stored in your Scrivenza account, for how long, and why — case reports, uploaded documents, and account data — see our Privacy Policy.

Compliance grounding

What the review is actually checked against

Every rule a case is reviewed against is written and documented, not an unexplained model instruction — built around FCA-regulated lending compliance and the patterns that actually turn up in real Financial Ombudsman Service decisions, the same evidentiary standard Consumer Duty holds a firm to: what it knew, or should reasonably have known. See how it works for how each finding traces back to the exact rule text that produced it.

See it before you commit to anything

Register free, no card required, and run real case reviews on real client statements.