Trust
Trust, honestly.
eri is an independent project run from Ontario. There is no compliance theatre on this page — what is true is marked live, what is not, is marked not yet. If your procurement checklist requires SOC 2 today, save us both the time.
Posture
PIPEDA (Canada)
liveeri is operated from Ontario and follows PIPEDA principles for the small amount of personal data the cloud side handles — consent on sign-up, access and deletion on request, breach notification where required.
GDPR / UK GDPR
liveAccess, rectification, deletion, and export are honoured for any account regardless of region. Standard Contractual Clauses cover transfers out of the EEA where sub-processors require them. Sub-processor list is at /legal/sub-processors.
CCPA / CPRA
liveCalifornia residents can exercise the right to know, delete, correct, and opt out of any sale or sharing of personal information. The operator does not sell personal information — there is nothing to opt out of, but the channel is open at phlotu@gmail.com.
Data residency
availableAccount data lives wherever the operator's database provider stores it (currently configurable per project). Model calls follow whichever provider you configure — that is a separate setting in the app.
SOC 2 / ISO 27001
not yeteri is run by one person. Formal audits like SOC 2 Type II or ISO 27001 are not in place and are not on a committed timeline. If your security review needs them, eri is not the right tool for you today. Honest.
HIPAA
not yeteri does not sign BAAs and is not designed for protected health information. Don't put PHI through eri.
Where data lives
The eri desktop app keeps your project files, voice frames, gaze data, and shell history on the machine they originated on. The cloud side — accounts and billing — lives with the operator's database and hosting providers (see /legal/sub-processors for the current list and regions).
Model calls follow whichever provider you connect. With BYOK, the request goes from your machine to that provider and the operator does not see it. With the default eri inference proxy, requests are forwarded without retaining request or response bodies.
Asking the operator
There is no NDA package, no auditor letter, and no compliance portal. There is one inbox: phlotu@gmail.com. The operator will answer your security questions honestly. The full architecture lives on the security page, and the vulnerability disclosure policy is at /security/disclosure.