Data Sovereignty Policy
Where your data actually lives, and how it’s protected.
XAP.ai is built for SME owners who share sensitive financial, strategic, and operational information with our agents. Below is a precise, layered breakdown — not a single blanket claim that rounds up to more than what’s actually true.
Data Protection, By Type
| Data Type | How It’s Protected |
|---|---|
| Your day-to-day ledger data (invoices, transactions, payroll — once XAP Books is live) | Encrypted, access-isolated database with the same security certifications and backup guarantees serious fintech platforms use — SOC 2 Type 2 certified infrastructure. Not zero-knowledge — a live, queryable ledger needs to be fast, which fully decentralised storage isn’t built for. |
| Your source documents (invoices, statements, filings) | Sovereign, client-verifiable, encrypted decentralised storage — not locked into one company’s cloud. |
| AI processing (every query touching your data) | Genuinely zero-knowledge for the duration of processing — hardware-verified confidential compute means even XAP.ai’s own operators cannot see prompts or outputs during inference. |
What we won’t say: that XAP.ai “cannot read” your ledger data. That would be false, and checkable by any technical due diligence team against our infrastructure providers’ own public security documentation. We’d rather be precise than sound more impressive than we are.
Key Commitments
- Storage: source documents in sovereign decentralised storage; transactional ledger in encrypted, access-isolated, SOC 2 certified managed infrastructure. Full transaction history retained — not just summaries.
- Inference: sensitive data processed only via TEE-protected environments. Cryptographic guarantees prevent even XAP.ai operators from accessing data during inference.
- Third parties: no client data transmitted to non-TEE miners or third-party proprietary AI providers without explicit client consent.
- Transparency: all data handling practices disclosed in our client agreements and platform documentation.
- Compliance: PDPA (Singapore), Privacy Act (Australia), NZ Privacy Act 2020, and applicable markets.
Your Data, Your Ownership
- You own: all raw data including your full transaction history — fully exportable at any time in standard format, deleted from all XAP systems within 30 days of account closure.
- XAP.ai owns: the derived intelligence layer created from anonymised patterns across client interactions — learned patterns, not your raw data, and never portable or exportable, since it’s genuinely generalised rather than yours specifically.
Last updated: 28 August 2026 | XAP Financial Technologies Pte. Limited | Singapore | xap.ai