Data residency
AvailablePaid accounts can choose US or EU storage. New session blobs route to the selected region, and an idempotent migration moves existing blobs when a user switches to EU.
Free accounts use the default region. Enterprise deployment requirements can be reviewed separately.
Encryption at rest and in transit
AvailableStored platform data is encrypted at rest with AES-256, and data transfers between clients and ReclaimLLM use TLS.
This baseline applies independently of the optional encrypted raw-session layer.
Encrypted raw session storage
AvailablePaid users and Enterprise organizations can add a separate encryption layer around full captured transcripts, tool results, file context, and raw session blobs.
Recovery keys are returned once for download, never emailed, and never stored in plaintext.
Admin-controlled decrypt access
AvailableEnterprise encryption is configured at organization scope. Organization policy controls whether admins and team leads may open encrypted member session details.
Metadata and aggregate reporting remain usable without opening every raw transcript.