Security
People tell Northwind things they’ve never said out loud, so this page errs on the side of specifics.
The architecture
Your voice is transcribed and processed by Northwind’s own model in a private, isolated environment. There is no call to an outside AI company anywhere in the conversation path. And to define “private environment” before anyone defines it for us: whether on machines we administer or a dedicated single-tenant deployment, the standard is the same — our model is the only AI that touches a conversation, the environment is isolated to us, the infrastructure provider retains nothing after the response, and it is contractually barred from training on or accessing content.
Encryption
TLS 1.2+ in transit; encryption at rest for conversations, memories and account data. Audio is not retained after transcription.
Retention, mechanically
You pick a window — 24 hours, 7 days, 30 days, or until you delete. Expiry deletes the conversation from live systems immediately and from backups within [BACKUP WINDOW]. Deleted means unrecoverable: not by support, not by engineering, not by legal process.
Subprocessors
The complete list: [HOSTING PROVIDER] (infrastructure). That’s it — the shortness of this list is the product.
The HIPAA question
We hold ourselves to HIPAA-grade controls — encryption, access control, audit logging. Northwind is not a healthcare provider, so HIPAA does not legally apply to your use of it; the standard is ours by choice, and “HIPAA-compliant” claims from apps like this one should make you suspicious.
Reporting a vulnerability
security@meetnorthwind.com — a human reads it, we respond fast, and we don’t pursue good-faith researchers. Machine-readable details in security.txt.