Governance
Security & Data Handling
One-page companion to Privacy and Terms. Credible for a small pilot — not an enterprise SOC 2 / ISO package. For trade secrets or regulated records, ask for a signed path before upload.
In one screen
| Topic | Public mill fact |
|---|---|
| Hosting | Operator-controlled plant in the United States; public door via Cloudflare tunnel to 127.0.0.1:8770 — not a multi-tenant SaaS farm |
| Who can open jobs | Sole operator (Carroll Miller) while materials exist; you via pickup/retrieve; no contractor content farm |
| Encryption in transit | HTTPS / TLS at Cloudflare |
| Encryption at rest | Not advertised as FDE. Job files live on local plant disk under OS permissions. No customer-managed keys. |
| Backups of your pile | None intentional as a product feature |
| Purge | Ready 72h if not downloaded; ~30 min after first ZIP download; fail 24h — job dir + brick + export ZIP |
| Doc content in logs? | Not by design as full-text logging; see § Logs |
| Breach target | Notify affected customers without unreasonable delay (pilot commitment) |
1. Hosting & network path
- Plant: manufacture and job store run on an operator-controlled Linux machine in the United States.
- Public door:
kbmill.com/www.kbmill.comterminate TLS at Cloudflare and reach the plant through a Cloudflare tunnel to local hopper port 8770. The plant is not marketed as an open WAN mill port. - Not: air-gapped, ITAR, multi-region active-active hosting, or a certified enclave.
2. Who can access jobs
- Carroll Miller (sole operator) — can read job materials on disk for ops, failed-job debug, abuse/malware review, and payment disputes. MFA on every surface is not claimed as a certified control set; operator account hygiene is the human layer.
- You — anyone holding the job retrieve / pickup path while Ready.
- No routine employee/contractor panel that browses customer uploads.
- Stripe — payment data on Stripe’s Checkout; not your PDF corpus.
- Cloudflare — sees connection/request metadata as traffic passes the edge; not used as a document store.
Longer form: Privacy §5.2.
3. Encryption
- In transit: HTTPS to kbmill.com (TLS at Cloudflare).
- At rest: We do not claim full-disk encryption, customer-managed keys, or field-level encryption of uploads. Files sit on the plant filesystem with directory permissions (hopper work root is operator-owned, not world-readable).
- If your diligence requires attested FDE / CMK, that is a signed / on-box conversation — not this public door’s advertised control.
4. Deletion mechanics (purge)
A purge loop on the plant (default about every 15 minutes) deletes expired jobs under the hopper work root:
- Job directory (uploads / working files)
- Manufactured brick directory for that job (when under the plant kbs root)
- Export ZIP for that job
- Pickup-hash index entry for that job
After a successful build, inbox upload copies are cleared early; the brick/ZIP remain until purge. Ready jobs: 72h if never downloaded; about 30 minutes after the first successful ZIP download (each download refreshes that grace). Failed jobs target 24h.
Short-lived classify/Go staging directories under the OS temp area are removed in a finally path after the request — they are not a second archive.
4.1 Systems that may still hold something
| System | Exists on this door? | Max retention we stand behind |
|---|---|---|
| Customer-job backups / snapshots (product) | No intentional feature | N/A — we do not run a “restore your pile” backup product |
| Plant job materials | Yes | Until purge clock (72h Ready if not downloaded; ~30 min after first ZIP download; 24h fail), then deleted under work root |
| OS crash dumps / swap remnants | Possible on any real machine | Not controlled by the purge daemon; we do not claim crypto-wipe |
| Cloudflare edge / security logs | Yes (provider) | Per Cloudflare retention — outside our purge; typically connection metadata, not a PDF archive |
| Stripe payment records | Yes | Per Stripe + our ledger needs (accounting / disputes) — not document corpus |
| Operational server / plant logs | Yes | Short ops window unless abuse or incident investigation |
| Optional Ready-notify queue | May exist if you opt in | Email + minimal ready signal — not the corpus; mill can run without sending mail |
Detail twin: Privacy §5.1.
5. Subprocessors (pinned)
| Provider | Role | Can uploaded document content reach them? |
|---|---|---|
| Cloudflare, Inc. | DNS, CDN, TLS, tunnel, bot/DDoS basics | In transit only as HTTPS bytes pass the edge — not retained by us as a document store. We do not use Cloudflare as object storage for your pile. |
| Stripe, Inc. | Checkout, authorize / capture / void, tax tools when configured | No — payment data, not your PDFs |
| Operator plant (KBMill) | Manufacture, job store, purge, ledger files | Yes — that is the processing location |
| Ready-notify SMTP / webhook | Optional email/webhook if enabled | No corpus in the notify payload by design; address + ready signal only if wired |
Default public mill path does not ship your PDFs to a separate third-party “document SaaS.” If remote GPU workers are ever used for customer jobs on this door, they will be named here before that happens.
6. Logs, tickets, and “improve the plant”
Operational signals we may retain (not as a hosted knowledge base):
- Job id, class/price, status chips, fail class / fail reason strings, timing, ledger events
- Filenames as supplied on upload (often appear in job metadata)
- Request logs: IP, user agent, path, timestamps, error text
We do not, by design, keep a debugging corpus of:
- Full document text, OCR output, chunk text, or embeddings after purge
- Customer job ZIPs as “support ticket attachments” in a helpdesk product (there is no Zendesk-style ticket pile on this door)
While a job is alive, extracted text / OCR / embeddings exist as part of manufacture under the job/brick directories — then fall under purge. Operator email threads you start may quote what you paste; don’t paste secrets into email.
7. Host controls (honest list)
- HTTPS at the door; tunnel to plant
- Per-job directories; path-guarded delete
- Caps + refuse-before-run; rate limits; zip-bomb / hostile-archive guards
- Offline-oriented manufacture posture (local cache; no mandatory hub phone-home mid-job)
- Optional container sandbox when configured — not a certified enclave claim
- Operator-gated ledger / purge surfaces
Not claimed: SOC 2, ISO 27001, published vuln-scan SLA, pentest certificates on a calendar, 24/7 SOC, MDM attestation, or universal MFA proof for every dependency.
8. Breach-notification target
If we become aware of unauthorized access to your mill uploads or job materials, we aim to notify affected customers without unreasonable delay (email on file and/or site notice). Pilot commitment — not liquidated damages. Enterprise timelines belong in a signed agreement.
9. Accountability contact
Carroll Miller, d/b/a KBMill
Email (privacy, security, signed-path): [email protected]
Web: https://kbmill.com
No public mailing address on this pilot page; email is the notice / contact channel.
US-centered service — see Privacy international note (not a GDPR compliance claim).
10. When this page is not enough
Ordinary / public technical documents in a short-lived pilot: this page + Privacy + Terms are meant to be credible and candid. Trade secrets, personal/regulated records, or contractual confidentiality: get a signed DPA / security schedule first — or keep processing on machines you control.