# SelbsAI — Security Overview

Version: 2026-08-08

This document is a pre-contract security summary. Customer-specific technical and organisational measures and data-processing terms are supplied where SelbsAI acts as a processor.

## Local operating boundary

- Core model inference runs on the customer-owned SelbsAI server appliance.
- Local use does not grant SelbsAI standing administrative access to the device.
- The installed runtime, model source, format, update posture, and verification information are recorded at handover.

## Online service boundary

Online systems are used for storefront operation, checkout, customer authentication, transactional email, shipping, support, and optional Pre-Load provisioning. The current service categories are documented in the Privacy Policy.

## Provisioning controls

- Private object storage for optional Pre-Load uploads.
- Authenticated, order-scoped signed upload URLs.
- File type, size, and per-order quota enforcement.
- SHA-256 recording where the browser can calculate it.
- Event logging for upload, provisioning, model QA, shipping, and deletion actions.
- Pre-Load retention normally no longer than 30 days after successful delivery unless otherwise agreed.

## Reporting

Security reports: security@selbsai.com

Machine-readable contact: `https://selbsai.com/.well-known/security.txt`
