Trust & Security
Your data stays yours
Surface uses AI to power design generation, but your designs, logos, and brand assets are never used to train AI models. Here’s how we protect your work.
AI Governance
Surface integrates multiple AI providers for texture generation. Every integration is governed by a strict no-training policy:
Data Protection
Your design files, brand assets, and account data are protected with industry-standard security:
Data Deletion
We support data deletion requests in compliance with GDPR, CCPA, and similar frameworks.
To submit a deletion request, contact us at support@surface3d.ai.
Transparency
Business Continuity
Surface is built on a distributed architecture designed for resilience:
Disaster Recovery
Our disaster recovery plan defines clear recovery objectives for every system:
Third-Party Sub-processors
Surface3D shares data with the following third-party services to operate the platform. AI providers receive data only during active generation requests and do not retain it.
| Provider | Purpose | Data Shared |
|---|---|---|
| Google (Firebase / Vertex AI) | Auth, storage, database, AI generation | Auth credentials, files, database records, AI prompts, reference images, logos |
| Supabase | Primary database | User profiles, org data, projects, credit transactions, activity logs |
| OpenAI | AI image generation (DALL-E) | AI prompts, reference images, logos — not retained after request |
| Replicate | AI image generation (Flux, Recraft) | AI prompts, reference images, logos — not retained after request |
| Stripe | Payment processing | Name, email, billing address, payment details |
| Vercel | Application hosting | Web traffic, IP addresses, request metadata |
| Resend | Transactional email | Name, email address |
Documentation
AI Governance Framework
No-training policy, data flow architecture, provider commitments, and deletion procedures.
Data Deletion Policy
Scope of deletable data, request process, timelines, and retention exceptions.
Service Level Agreement
Uptime commitments, support response times, remediation approach, and enterprise SLA options.
Business Continuity Plan
Continuity strategies, communication plan, and recovery procedures for all critical systems.
Disaster Recovery Plan
RTO/RPO targets, backup strategy, scenario playbooks, and post-recovery validation.
Questions?
Reach out during your security review process and we’ll get you what you need.
support@surface3d.ai