Security

Redaction is not the last step. It is the whole process.

Four passes run before a single byte is priced as deliverable. You read the full report and countersign it before the transfer window opens.

Nothing identifying ever leaves your building.

  • Names, email addresses, phone numbers, street addresses and government ID numbers are removed before delivery.
  • Credentials, API keys, tokens and payment instruments are detected and destroyed. They are never transferred.
  • You read and countersign a complete redaction report before the transfer window opens.
  • One-way encrypted lift into an isolated enclave. No resale rights, no syndication, no third parties.
  • You keep everything. You are licensing a refined copy, never surrendering the original.

An illustration of the redaction pipeline: as the document is scanned, all 13 identifiers are replaced with redaction bars and all 7 credentials are removed entirely, before the redaction report is issued for countersignature.

The pipeline

Four passes, in this order, every time.

Pass 01

Deterministic strip

Pattern and format matching removes email addresses, phone numbers, postal addresses, national ID formats, card numbers, IBANs, API keys, bearer tokens and private key blocks. Anything that matches a known shape is destroyed, not masked.

Pass 02

Entity resolution

Named-entity extraction catches what patterns miss: people, in every spelling, nickname and signature block they appear in. Each identity is replaced with a stable pseudonym so the conversation still reads coherently, and the mapping table is never transferred.

Pass 03

Contextual sweep

A model pass reads for identity that survives the first two — an unusual job title in a small office, a named account paired with a named region, a medical detail attached to a role. Anything that could re-identify a person in context is removed.

Pass 04

Human adjudication

A reviewer samples the output against your exclusion list and your regulator's standard. Findings go into the redaction report you countersign. Nothing enters the transfer window until you have signed it.

Posture

The answers your security team wants in writing.

Transfer direction
One-way. Bounty holds no standing access to your tenant at any time.
Encryption
TLS 1.3 in flight, AES-256 at rest, customer-scoped keys inside the enclave.
Enclave
Isolated per engagement. No shared storage, no cross-corpus joins, no operator shell.
Retention of mapping tables
Destroyed on delivery confirmation. They are never part of the transferred corpus.
Resale rights
None. Licenses forbid resale, redistribution, syndication and publication.
Your originals
Untouched. You license a refined copy and keep everything you had.
Sub-processors
Named in the DPA before signature. No additions without written notice.
Right to withdraw
Any time before transfer. The manifest is deleted on request.

Security questionnaires, DPAs and sub-processor lists go to security@databounty.ai. We answer in full before a bounty is issued, not after.

Read the pipeline. Then read your own report.

Every engagement produces a full redaction report before transfer. You sign it, or nothing moves.