Security and data handling
Current architecture · last updated 17 August 2026
What is live today
The public website and local validator run on Cloudflare Pages. A small Cloudflare server function starts subscription checkout using a restricted Stripe key; it receives only the selected reporting route. Stripe hosts the payment page and collects business and payment details. There is no UK Filing account system, customer-file database or file-upload endpoint. Selected file content, names and validation results remain in the browser and are never included in checkout. Do not send invoice files or confidential framework data by ordinary email.
Infrastructure
Cloudflare delivers the static pages, validator code and public reference data, runs the checkout-session function and provides transport encryption and network-level security. The Stripe secret is stored as an encrypted Cloudflare secret and is not shipped to the browser. Stripe hosts checkout and payment data; the email address uses Hostpoint infrastructure in Switzerland. No production location is claimed for server-side MI-file processing because that file backend has not been selected or deployed.
Current service providers
| Provider | Current role | Location | Customer files |
|---|---|---|---|
| Cloudflare, Inc. | Static site, validator code and public reference-data delivery; network security | Global network, including the United States | Not transmitted by the browser validator |
| Stripe group entities | Hosted checkout, recurring billing, payment authentication and fraud prevention | Global service; relevant entities and transfers are described by Stripe | Not transmitted; checkout receives only the selected reporting route |
| Hostpoint AG | Email hosting | Switzerland | Must not be sent by ordinary email |
Local validation safeguards
The validator has no network call for customer-file content, results or usage telemetry. It accepts only the advertised extensions, limits files to 20 MB, caps displayed findings and populated rows, escapes all file-derived text before displaying it and uses a restrictive Content Security Policy. Refreshing or closing the page clears its working state. If the post-check subscription message is dismissed, only its expiry time is kept locally for 14 days; it is not sent to Dali AI. Starting checkout posts only gca or hte to the same site, which creates a short-lived Stripe Checkout Session and redirects the browser to Stripe.
Subscription management
The management link opens a dedicated Stripe customer-portal configuration. Stripe verifies the checkout email with a one-time passcode. The portal permits cancellation at the end of the paid period, payment-method updates and invoice access. UK Filing does not collect a portal password or passcode.
Requirements before server-side files are accepted
A future paid backend requires a named processing and storage provider, encryption in transit and at rest, access logging, tested deletion, backup rules, incident handling, a customer data processing agreement and prior approval of every sub-processor. The privacy notice and this page must be updated against the deployed architecture before any server-side upload control is enabled.
What we do not claim
Dali AI currently claims no ISO 27001 certification, Cyber Essentials mark, fixed MI-file processing region, service-level percentage or server-side automated deletion guarantee for UK Filing. Such statements will appear only when implemented and verifiable.
Reporting a problem
Write to mi@dali-ai.ch without attaching customer data. This address is monitored for security and privacy enquiries.