DSAIL Quickstarts Guides Compare REST MCP tools Errors Legal Support

Data handling

Exactly what the DSAIL hosted service stores, what it never does with it, what it must never be sent, and how the one derived field — a category label from a published vocabulary — is kept from ever pointing back at anyone's policy.

Version 2026-09-14. Draft pending review by outside counsel. Issued by Jaxon, Inc. as the technical statement behind the hosted-service terms and privacy notice, which sit under Jaxon's Terms and Conditions and Privacy Policy. Written for two readers, a procurement reviewer and a model. No marketing.

What we store

ObjectContentsWhy
Ruleset sourceyour normalised DSAIL text, at its content hashto compile it when you ask for a check by hash, and so an approval can name exact bytes
Ruleset name and revision linka name, the hash it points at, the parent hashso a later conversation finds what an earlier one saved
Approvalapprover, note, timestamp, ruleset hash, unit-library hasha person's sign-off bound to exact bytes
Unit libraryconverters: two unit names, a factor, an attributiona rate is a policy decision a person supplied
Category labelvocabulary version, a level-one id, a level-two id or null, a confidence bucket, a declined flagsee below
Credentiala hash of the token, its grade, its expiry, a namespace, the door and product surface it was first issued throughto scope storage to its owner, and to know which surface brings people in
Identityyour provider's subject identifier and your organization nameso your rulesets are yours, and your colleagues' are the same project's
Organization and projectan organization name, a project id, and the link between themthe unit that owns a ruleset library and an allowance
Entitlementa tier, a payment-provider customer and subscription reference, a statusto know what the account bought
Usage countyour organization's running total of Jaxon Verified Units consumedto report and enforce an allowance
Usage eventmetadata only (listed on the privacy page)so usage can be metered and the product understood in aggregate

Not stored: your e-mail address, your name, your picture, your client address, your card, your billing address. The address is used once at sign-in to work out which organization you belong to and then discarded; if it is at a public mailbox provider, what is recorded is an irreversible digest of it rather than the address or its domain.

What we do not do with it

What you must not send, and what we are not

The service is built to hold policy rules, not the material a policy governs. It holds no FedRAMP authorization, no DoD provisional authorization, no CJIS agreement, no HIPAA business associate agreement and no PCI attestation; it runs in a commercial AWS region in the United States, operated by Jaxon personnel who are not screened for clearance. A Jaxon administrator with access to the host could, in principle, read stored source bytes; the terms bind them not to, and no procedure Jaxon operates does.

So a ruleset must never carry classified information, Controlled Unclassified Information, ITAR- or EAR-controlled technical data, Criminal Justice Information, protected health information, cardholder data, or personal data beyond the approver names and notes an approval record needs. DSAIL source is authored from a policy and can carry policy language verbatim in rule names, string literals, comments and notes — write it so that it does not. The published vocabulary's security_classification domain is a category for policies about controlled information; the controlled information itself does not belong on this service. Jaxon does not screen for it and has no obligation to treat what you submit as controlled.

Results are conclusions, not determinations

Every result is what the rules concluded about the claim values you supplied, per assertion, in the engine's four words — TRUE, FALSE, UNKNOWN, AMBIGUOUS — each naming the assertion that decided it. The service publishes no overall verdict and makes no compliance or legal determination. Whether the claim values faithfully describe a document is your extraction's responsibility and sits outside the formal guarantee: the service never sees the document, and cannot know whether a value is true of it. UNKNOWN is a legitimate result meaning a needed claim was not determined, not a failure and not a pass.

The one derived field, and how it is kept honest

The single fact the service derives about a ruleset is an application-domain label: which of fourteen broad domains the policy belongs to (level one), and optionally a narrower topic (level two).

Aggregate figures

Jaxon computes, internally and in aggregate, what share of rulesets fall in each domain and topic, and how features such as the unit library, revisions and approvals are adopted. The terms grant that right expressly and subject to the rules below, which a reviewer can check rather than take on trust:

Retention and deletion

Rulesets, approvals and unit libraries: until you ask for deletion, or thirty days after an account ends other than for your breach. Deletion removes the objects and their metadata rows from the live store at once. Backups: daily for 35 days, weekly for 120, monthly for 400, in-region and cross-region alike; a deleted object persists in those copies until they age out and is not restored selectively. Usage events and CDN access logs: 400 days.

Security incidents

On confirming an incident affecting stored content or an account, Jaxon notifies the affected customers without undue delay and within 72 hours, stating what was affected. The tables above bound what that can be.

Who can reach what

IdentityReach
The serviceits own volume, its own log group, the labeling and account-class settings
Jaxon deployer (MFA)build, push and deploy the image; no read of the store
Jaxon dashboard viewer (MFA)the usage dashboard and its log group; nothing else in the account
Jaxon analytics (MFA)the usage-event log group, read-only; explicitly denied the host, the volume, the backups, the settings and the registry
Jaxon administrator (MFA)the infrastructure, through Terraform; the host, through Systems Manager, for the procedures the runbook names — bound by the confidentiality obligation in the terms
Amazon Web Servicesthe sole hosting subprocessor; holds the encrypted volume and backups
Auth0 (Okta)your sign-in credentials; receives no ruleset, claim, name or label
Stripeyour payment details, if you subscribe; receives your organization name as a reference and nothing else

Related: Terms of service, Privacy, Published vocabulary.