Why Sealed

Before AI reads your customs records, know where they go.

Popular AI tools keep what you upload, and some train on it.⁠[1] Ours never trains on your records; with Sealed, no outside AI reads them, no one sees them without your consent, and a receipt proves it.

Verify a receipt

About 3 minutes on a sample file. Your email and name open it. We never ask for your ACE login or bank details.

Your records

What do your customs records say about your business?

More than any other file you'll hand a vendor. The law requires each document to carry the details a competitor wants most.

Put together, these files show your landed cost and your margin by product and by lane.

That is as true for a furniture importer or an apparel brand as for a defense supplier.

What each document shows
DocumentWhat it showsWhy it's there
Commercial invoiceYour supplier, your buyer, the purchase price of each item, every charge, rebates, and "assists such as dies, molds, tools, engineering work"Required on every commercial invoice⁠[2]
Export record (EEI)Your customer: the ultimate consignee's name and address, plus product codes, values and, for defense articles, license detailsRequired on every export filing⁠[3]
Entry summary (CBP 7501)Supplier, tariff line, value and duty by program, entry by entryHow you declare imports to CBP
Bill of materialsWhat goes into what you makeNeeded for manufacturing claims
Bills of lading and manifestsWho ships to whomAlready searchable at scale: one site offers search across 712,390,974 customs shipment records⁠[4]

Importers already pay attention to this: CBP lets an importer ask to keep its name off public vessel manifests,⁠[5] and Census treats export filings as confidential by law.⁠[6]

Does this matter if your industry isn't regulated?

Yes. Your entries and invoices show what you pay each supplier. Your export records name your customers. Together they show your margin by product.

  • Shipment manifests are public. Your prices are not. U.S. ocean import manifests, with shipper, consignee, description and weight, are public, and data firms resell them. They carry no values. Invoice prices, margins and customers stay private.⁠[7] A drawback file puts the prices and the customers side by side.⁠[2]⁠[3]
  • A secret has to be kept secret. A trade secret stays protected only while you take "reasonable measures" to keep it secret.⁠[8] In January 2026, in Trinidad v. OpenAI, a federal court dismissed a trade-secret claim because the material had been shared with ChatGPT under OpenAI's terms. The case concerned consumer terms; enterprise terms have not been tested.⁠[9]
  • Sharing with AI is common. In Cisco's 2024 survey of privacy and security professionals, 48% admitted entering non-public company information into generative AI tools.⁠[10]

Sealed gives you a receipt you can keep, showing the run was sealed. Whether that counts as a "reasonable measure" is for your lawyer to judge. A receipt doesn't decide it. If you protect your supplier prices, formulas or customer lists as secrets, Sealed is recommended.

Where it goes

Where do your documents go when an AI agent reads them?

In a typical AI pipeline, a copy of your files can exist in six places.

Typical AI agent

  1. 1The vendor's storage
  2. 2The vendor's servers
  3. 3An AI model provider
  4. 4Logs and review queues
  5. 5People
  6. 6Other vendors

Sealed

  1. 1Encrypted files only
  2. 2Our servers, inside one sealed machine
  3. 3No AI model provider
  4. 4Logs with no document content
  5. 5Only the people you approve
  6. 6Vendors with no document content

Standard

  1. 1Our cloud, encrypted at rest
  2. 2Our servers
  3. 3An outside AI provider, on terms that bar training
  4. 4System logs with no document content
  5. 5Named staff, every access logged
  6. 6Hosting provider and backups, on our subprocessor list
Read the diagram as steps
  1. In a typical AI pipeline, documents can pass through storage, servers, an outside AI model provider, logs, people and other vendors.
  2. In Sealed, processing happens inside one sealed machine with no model provider and no staff access.
  3. In Standard, an outside AI provider may process them, only on terms that bar training, and every staff access is logged.

Encryption protects files at rest and in transit, not while they are being read. That is when an AI agent needs them.

The six places, in words

Each is a place it can be kept, read or lost.

  1. The vendor's storage, where your upload lands.
  2. The vendor's servers, where files are decrypted so the agent can read them.
  3. An AI model provider, if the vendor sends your text to a third party's model.
  4. Logs and review queues, at the vendor and the model provider.
  5. People: support staff, reviewers and contractors with access.
  6. Other vendors: analytics, support desks and backups that touch your data.

In our two modes

Sealed

Sealed goes further: place 3 doesn't exist, the reading happens inside one sealed machine, and no one sees your documents without your consent.

Standard

In Standard, an outside AI provider may process your documents, only on terms that bar training. Only named NexQloud staff can open them, and every access is logged.

The risks

What can go wrong, and what does each mode remove?

Risks that sit with us, where Sealed goes further

Can a person read your documents?

Sealed

In Sealed, there is no staff access path: exceptions go to you or your broker, and no one sees your documents without your consent.

Standard

In Standard, only named NexQloud staff can open your documents, to fix an exception or answer a support request, and every access is logged. You can get your account's access log.

The record

At most AI services, yes, under defined conditions. That is how abuse is caught and support is given. It is also an access path.

  • Google says "a subset of chats are reviewed by human reviewers (including Google's trained service providers)".⁠[11]
  • Microsoft lets authorized employees review prompts and outputs that its abuse system flags.⁠[12]
  • OpenAI lets authorized employees, and "specialized third-party contractors," access business data for support, abuse review and legal compliance.⁠[13]

Access paths get abused

  • In 2019 a Google language reviewer leaked confidential audio from a human-review program.⁠[14]
  • In 2025 criminals bribed a small group of Coinbase support agents to copy customer data from support tools.⁠[15]

To be fair

Those companies disclosed the abuse and acted on it. The point is not that they are careless. It is that any path a person can use, a person can misuse.

Isn't "SOC 2, encrypted, access-controlled" enough?

For everyday records, it often is, and our controls are SOC 2 Type 2 audited. What controls can't do is prove that the operator itself can't read your files.

Sealed adds proof you can check yourself. Standard runs on our controls, and the trust center shows their audit status.

Two kinds of assurance

Those are real controls, and you should expect them from any vendor. They protect your files from outsiders, and an audit can test that they work. What controls can't do is prove that the operator itself can't read your files, because the operator holds the keys while the files are being read.

Two kinds of assurance

Controls an audit can testProof you can check yourself
"Only named staff can open your documents, and every access is logged."The machine's measured code has no access path, and a hardware-signed report shows that code is what ran.
"We delete your files on a set schedule."The working copy's keys are erased, and the run's signed receipt records it.
"Any outside AI provider's terms bar training, and we don't train on your files."No outside model provider is in the path, and the model's weights are fixed by a published hash.

Buyers want outside evidence

In Cisco's 2024 survey, 98% of respondents said external privacy certifications are important in buying decisions.⁠[10] An audit of a vendor's controls is one kind of outside evidence. A Sealed receipt is another. It is not a certification, but anyone can check it.

Risks from an outside AI provider. Sealed removes that step.

Can your documents end up training an AI model?

Your documents are never used to train any model. Standard may use an outside AI provider, only on terms that bar training.

The record

It depends on the plan, the settings and the terms, and you usually can't see which ones a vendor's agent uses.

What the record showsDateSource
OpenAI: "When you use our services for individuals, such as ChatGPT and Codex, we may use your content to train our models." Users can opt out.Updated Sept 2026⁠[16]
Anthropic: "We will train new models using data from Free, Pro, and Max accounts when this setting is on." Users who allow it get five-year retention.Aug 28, 2025⁠[17]
Google, Gemini Apps: "Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services, including machine-learning technologies."Sept 24, 2026⁠[11]
Google, unpaid Gemini API: "Do not submit sensitive, confidential, or personal information to the Unpaid Services."Apr 28, 2026⁠[18]

To be fair

Business and API plans at OpenAI, Anthropic, Google and Microsoft do not train on customer content by default.⁠[17]⁠[13]⁠[19]⁠[20] The risk is in the gap: consumer and free tiers can, and a colleague with a personal account, or a vendor prototyping on a free key, is on one of them.

Why it matters once it happens

Researchers showed in 2023 that an attacker could make a production chatbot "emit training data at a rate 150x higher than when behaving properly".⁠[21] Data that goes into training can come back out. Opting out later doesn't undo it: in 2024 LinkedIn used members' data for AI training before updating its terms, and TechCrunch reported that opting out "won't affect training that's already taken place".⁠[22]

In Sealed, the model's weights hash is also published, and each receipt names the weights that ran.

If the vendor's terms change, what happens to your data?

No outside AI provider's terms apply in Sealed. In Standard, the provider's terms can change. Our own terms can change too. We give notice before any change, and changes are never retroactive.

The record

The rules for your data are only as fixed as the contract behind them.

  • In February 2024 FTC staff warned AI companies that adopting "more permissive data practices... through a surreptitious, retroactive amendment" may be unfair or deceptive. They noted that data-hungry firms "may find that the readiest source of crude data are their own userbases".⁠[23]
  • In 2025 one major provider moved its consumer plans to an explicit training choice, with a deadline to decide.⁠[17]
  • FTC action comes after the fact. It does not stop a change before your files are used.

How long does a copy of your documents last?

Sealed

Sealed erases the working copy at the end of each run and keeps a signed receipt.

Standard

Standard keeps your documents for the engagement, then deletes them on a published schedule. The AI provider's retention rules also apply.

The record

Longer than most people assume, even without training.

What the record showsDateSource
OpenAI "may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse."Jan 8, 2026⁠[13]
Anthropic deletes commercial API data within 30 days by default, but keeps flagged inputs and outputs "for up to 2 years."July 1, 2026⁠[24]
Google keeps Gemini chats seen by human reviewers "for up to three years," even after the user deletes them.Sept 24, 2026⁠[11]
A 2025 court order in the New York Times case made OpenAI keep consumer and standard API content, including deleted chats, until September 26, 2025. Some of that data remains on legal hold. Enterprise, Edu and zero-data-retention customers were exempt.June 5, 2025; updated Oct 22, 2025⁠[25]

A copy that exists can be ordered by a court, reached in a breach, or read by someone with access. A copy that has been erased can't.

What about the vendors your vendor uses?

Only Sealed keeps your documents away from outside AI providers and their vendors.

The record

Every tool connected to an AI service is another door.

  • In August 2025 attackers used stolen access tokens from an AI chat agent, Salesloft Drift, to pull data from many companies' Salesforce systems. Salesloft and Salesforce revoked the tokens on August 20.⁠[26] Cloudflare, one of the affected companies, found 104 API tokens in its stolen support cases, rotated all of them, and warned that anything pasted into support "should now be considered compromised".⁠[27]
  • In November 2025 an analytics vendor used by OpenAI was breached, exposing API users' profile details. No chat or API content was exposed, and OpenAI stopped using the vendor.⁠[28]
  • In January 2025 researchers found an AI provider's database of chat histories open to the internet. It was secured promptly after they reported it.⁠[29]
  • In August 2025 more than 370,000 shared conversations from one AI assistant became searchable online, along with some uploaded "image files, spreadsheets and some text documents." The provider did not respond to Forbes's questions.⁠[30]
Sealed

In Sealed, hosts and storage hold only encrypted data, and no analytics tool or support desk receives your documents.

Standard

In Standard, your documents stay with our hosting provider and any outside AI provider we use, and every vendor we send them to is on our published subprocessor list.

Only Sealed keeps your documents away from outside AI, so incidents like the last three above have no path to them through Sealed. Standard may use an outside AI provider, on terms that bar training, but a breach at the provider or one of its vendors could still reach them. Connections to your own systems are read-only, and you can revoke them at any time.

In both modes, our billing and support systems hold claim totals and contact details, like any company's.

A risk in the documents themselves

Can a document trick an AI agent?

Yes. No vendor can truthfully promise its agent can't be fooled.

The same limits apply in both. The model can only fill fixed forms. It has no tool that sends data out.

Code re-checks the arithmetic. And a licensed broker decides before anything is filed. Sealing doesn't change this risk by itself.

The record

An AI agent follows instructions in text, and it can't always tell your instructions from text an outsider wrote. Your supplier invoices and shipping documents are written by outsiders.

What researchers showedDateSource
Microsoft 365 Copilot (EchoLeak). One email with hidden instructions led Copilot to leak data from its context, with no click by the user. Rated 9.3 of 10. Microsoft fixed it; there was no evidence it was used in the wild.June 2025⁠[31]⁠[32]
Salesforce Agentforce (ForcedLeak). Instructions planted in a web form made the agent send customer data to an outside domain. Rated 9.4. Salesforce fixed it.Sept 2025⁠[33]
Slack AI. Instructions posted in a public channel got Slack AI to reveal data from a private channel. Researchers noted the same attack could hide in a PDF's white text. Salesforce patched it.Aug 2024⁠[34]
An agent connected to GitHub. A malicious public issue got an agent to leak data from private repositories. The researchers call it an architectural problem, not a bug.May 2025⁠[35]

What the standards bodies say

  • OWASP, the security community's reference list (2025): "it is unclear if there are fool-proof methods of prevention for prompt injection".⁠[36]
  • NIST found in January 2025 that new attacks raised the success rate of agent hijacking "from 11% for the strongest baseline attack to 81% for the strongest new attack".⁠[37]

What a vendor can control is what a fooled agent is able to reach and send.

If data leaks

What happens to a business when trade data leaks?

Competitors learn your prices and partners. If your records carry legal duties, a leak can also become a regulatory event.

What a leak costs
OutcomeWhat the record showsSource
Competitors learn your prices and partnersSupplier relationships are already searchable from shipment data. The prices, assists and customers behind them are not public until a file leaks.⁠[4]⁠[7]⁠[2]⁠[3]
The billIn IBM's 2025 study of 600 organizations, the average U.S. breach cost $10.22 million, and organizations with high levels of unsanctioned "shadow AI" had breach costs $670,000 higher, on average, than those with little or none. These are averages, not a forecast.⁠[38]
State actors want itA May 2025 joint advisory from NSA, FBI, CISA and allied agencies described Russian military intelligence hunting logistics data: "sender, recipient... container registration numbers, travel route, and cargo contents."⁠[39]
Regulated trade and your data

Get started

Prove it on every claim.

Run the demo in Sealed mode. About three minutes.

  1. 01

    Choose Sealed.

    Pick Sealed mode when you upload your records.

    WhoYou

  2. 02

    The agent works inside the enclave.

    Your records are read inside AMD SEV-SNP hardware.

    WhoThe agent

  3. 03

    You get a signed receipt.

    The working copy is erased. Anyone you share the receipt with can verify it.

    WhoYou

Your email and name open the demo. We never ask for your ACE login or bank details.

Book a discovery call
Ready now? Start a claim

Honest limits

What does Sealed not protect against?

  • We trust AMD's hardware, firmware and keys.
  • Physical and side-channel attacks are outside AMD's model, so who can reach the hosts matters.
  • A receipt is only as current as the platform's patches. It proves which code ran, not that the code has no bugs.
  • Outputs show what they must. "Erased" means cryptographic erase.
  • You and your broker keep the records CBP requires.
  • Sealed is not a CMMC, FedRAMP or ITAR credential, and it protects secrecy, not uptime.
Read all ten limits
Every risk, side by side

Both modes use the same checks and the same licensed broker. In Sealed mode, your documents are read inside AMD SEV-SNP confidential virtual machines. Their memory is encrypted with a key managed by the AMD Secure Processor built into the chip, not by us. No one sees your documents without your consent. Each run ends in a receipt you can check against AMD's keys.

RiskTypical AI agentSealedStandardWhat still applies
Risks that sit with us
People readingSome providers' reviewers, for flagged or sampled content, and the vendor's own staff under its own rulesNo staff review path. Exceptions go to you or your broker. No remote login or debugging in the measured image.Named NexQloud staff, only for exception review and support, with every access loggedPhysical attacks on the memory bus are outside AMD's threat model. Who can reach the machines matters.
ProofThe vendor's word and its auditsA receipt for every run, checkable against AMD's keysOur controls and your account's access log, with audit status on the trust centerA receipt proves which code ran, not that the code has no bugs.
Risks that come with an outside AI provider
TrainingMay send your documents to an outside AI provider, whose plan and settings decide whether they train a modelNo outside AI provider. Never used to train any model, and the model's weights are fixed by a published hashAn outside AI provider may be used, on terms that bar training. Never used to train any modelYour staff can still paste files into consumer tools. Give them a sanctioned path.
Changing termsThe provider's terms and the vendor's can changeNo AI provider's terms in the chain, and each receipt names the exact code release that ran. A later change can't reach a working copy that no longer exists.The AI provider's terms bar training, but they can changeOur own terms can change too. We commit to notice before any change, never retroactive.
Copies that outlive the jobProvider copies kept for set windows, longer if flagged or held under a court orderThe working copy is cryptographically erased at the end of the run. A processor that keeps no documents has none to produce.The AI provider's own retention rules apply. Ours are kept for the engagement, then deleted on scheduleWe keep claim totals, receipts and billing records. You and your broker keep the records CBP requires.
Vendors' vendorsThe provider's own vendors, plus the agent's integrations and support toolsYour documents never reach an outside AI provider, analytics tool or support desk. Hosts hold encrypted data only.The AI provider's own vendors, and a breach at the provider. Every vendor we send your documents to is on our published subprocessor listBilling, CRM and support systems hold claim totals and contact details, like any company's.
A risk in the documents
Hijacking by documentsDepends on what the agent can reach and sendDesign limits what a fooled agent can do: no outbound connections except to you and your broker, no tools that send data out, structured outputs, arithmetic re-checked by deterministic code, and a licensed broker who decides before anything is filedThe same design limitsNo vendor can promise immunity. Neither do we.

Read the full list at /sealed/#limits.

Ten questions

What should you ask any AI vendor before it reads your records?

Ten questions for any vendor, including us.

The ten questions
  1. Does any outside AI model provider receive my documents? Which one, on which plan?
  2. Is my data used to train any model? Show me the clause.
  3. How long are copies kept, including logs, backups and review queues?
  4. Who can read my documents, when, and how is each access logged?
  5. Can you prove any of that with something I can check myself?
  6. What happens to my data if your terms change?
  7. Which other vendors touch my documents?
  8. What can your agent reach and send? Can a document make it send data out?
  9. Who decides what is filed with CBP? Is that person a licensed customs broker?
  10. Do you ever ask for my ACE login or bank details? (The right answer is no. CBP warns about anyone who does.⁠[44])

Read our answers

Which mode

Which mode fits your records?

Sealed

Sealed fits records that must stay private:

  • Trade secrets. Supplier prices, formulas or customer lists you protect as trade secrets or under a nondisclosure agreement.
  • A contract that requires it. A customer or contract that requires confidential processing.
  • Export-controlled goods or defense work (ITAR, EAR, DFARS). Sealed protects your export records, contracts and prices. Leave export-controlled technical data out of the file in either mode; drawback doesn't need it.

It also fits anyone who wants proof they can check, for a customer, an auditor or a security review.

Standard

Standard is enough when your records hold nothing you would mind a named, logged NexQloud specialist seeing, or an outside AI provider processing. It costs 2 points less.

An outside AI provider may process your documents, only on terms that bar training. Nothing trains on them.

Only named NexQloud staff can open them, to fix an exception or answer a support request, and every access is logged.

Published fees, charged after CBP pays. We never ask for your ACE login or bank details.

If CBP pays you

If CBP pays you $1,000,000, the fee is $175,000 with Sealed, an effective rate of 17.5%. With Standard it is $155,000, or 15.5%. You keep $825,000 or $845,000.

Sealed

Private by default. Provable on request.

$175,000

Effective rate
17.5%
You keep
$825,000
Standard: 2 points less

May use outside AI. Staff access logged.

$155,000

Effective rate
15.5%
You keep
$845,000
Show the math
Sealed
20% × 500,000 + 15% × 500,000 = $175,000 (17.5%)
Standard
18% × 500,000 + 13% × 500,000 = $155,000 (15.5%)
Sealed and Standard, side by side

Same checks, same licensed broker. With Sealed, your records stay private, and a receipt proves it. Standard may use outside AI, on terms that bar training, and logs every staff access.

QuestionSealedStandard
Outside AI model providerNone. The model runs inside the sealed machine.May be used, on terms that bar training
Used to train any modelNever, and the model's weights hash is publishedNever
Who can read your documentsOnly the people you approve, such as your broker. Exceptions go to you or your broker.Named NexQloud staff, only for exception review and support, with every access logged
After the runWorking copy cryptographically erased; signed receipt keptKept for the engagement, then deleted on schedule
What you can checkA receipt for every run, checked against AMD's keysOur controls and your account's access log, with audit status on the trust center
Fee on $1,000,000 recovered (lookback)⁠[45]$175,000 (17.5% effective)$155,000 (15.5% effective)
Fee schedule20%, 15% and 12% by lookback tier18%, 13% and 10% by lookback tier

You choose when you start, and you can change modes for later uploads.

Demo

Run the demo

Watch the agent turn a sample file into a claim folder. About 3 minutes.

We'll email you the link and add you to the waitlist. Unsubscribe anytime. We never ask for your ACE login or bank details.