Separate QA runtime; production certification still pending
Trust and data handling
This page gives buyers and technical reviewers a codebase-grounded view of AnswerLattice infrastructure, providers, retention, and current compliance claims. It is operational documentation, not a certification or contract.
Last reviewed: July 19, 2026
Separate QA runtime; production certification still pending
Reviewed before users receive support guidance
No unsupported certification, DPA, or residency claim
Operational provider map
These are the active or configurable provider categories visible in the AnswerLattice runtime. Contractual terms and geographic processing requirements still need buyer-specific review.
Application hosting and domains
Vercel
Serves the AnswerLattice Next.js application and manages configured public and hosted-help domains.
Application requests and deployment metadata required to serve the product.
Database, authentication, storage, and functions
Google Firebase and Google Cloud
Stores workspace data, authenticates product access, holds scoped files and compiled context, and runs AnswerLattice Cloud Functions.
QA uses the separate AnswerLattice Firebase project. The separately defined production target still requires deployment and launch certification.
AI-assisted processing
Google Gemini
Supports configured drafting, extraction, embedding, fallback, and review-assistance paths.
Generated output remains draft or fallback material until the applicable review path approves it as official support.
Billing
Razorpay
Creates checkout, subscription, and top-up provider records.
AnswerLattice stores bounded billing identifiers, status, amount, currency, and lifecycle summaries, not payment-card details.
Email delivery
Configured SMTP service
Sends selected support and workflow notifications when email delivery is configured.
Delivery uses the intended recipient, subject, bounded message content, and compact delivery diagnostics.
Cache and rate limiting
Upstash Redis when configured
Supports bounded cache and public-request rate-limit paths.
The durable workspace source of truth remains in AnswerLattice Firebase.
Public website analytics
Plausible and Google Analytics when configured
Measures public website activity only after analytics consent.
The public website stays on essential behavior when analytics is declined or no measurement setting is configured.
Implemented retention
These windows describe implemented product retention controls. Durable workspace truth, approved knowledge, billing state, and extracted source text have different lifecycle requirements.
30 days
Temporary retrieval cache with expiry and cleanup.
90 days
Bounded runtime trace used for feedback, support gaps, and troubleshooting.
90 days
Compact operational and delivery diagnostics.
2 days
Short-lived abuse and delivery-volume counters.
365 days
Buyer or support follow-up records with an expiry field.
365 days
Scheduler cleanup bounds the raw signal window.
90 days
Compact historical product-friction measurements.
Not retained after extraction
Extracted, redacted source text and review lineage remain until removed or a later lifecycle policy applies.
Claim status
Security controls and product separation are evidence. They do not automatically create an audit certification, legal agreement, or residency commitment.
No public certification claim
AnswerLattice does not display an independent security certification badge on the basis of product controls alone.
Not published as a standard public document
A buyer that requires a DPA should raise that requirement before purchase so legal and provider terms can be reviewed explicitly.
Not published
The operational provider map on this page is factual product documentation, not a contractual subprocessor schedule.
No public residency promise
If a specific processing or storage region is mandatory, it must be confirmed as a contractual deployment requirement before purchase.
No public no-training or zero-retention claim
Those claims depend on the active Gemini billing tier, feature use, abuse-monitoring status, and account configuration. They must be verified against the deployed provider account before purchase or publication.
Handled through a scoped support review
AnswerLattice does not claim a one-click full-workspace deletion flow. Contact the team to confirm scope, billing state, legal constraints, and deletion evidence.
Share your required controls, processing regions, legal terms, deletion expectations, and rollout scope before purchase. Requirements that are not documented here are not assumed to be available.
Request security review