Invite jobs running Public pilot mill · Workspace open
KBMILL Security Enter the plant

Governance

Security & Data Handling

Last updated: 2026-09-14 · Operator: Carroll Miller, d/b/a KBMill · [email protected]

One-page companion to Privacy and Terms. Credible for a small pilot — not an enterprise SOC 2 / ISO package. For trade secrets or regulated records, ask for a signed path before upload.

In one screen

TopicPublic mill fact
HostingOperator-controlled plant in the United States; public door via Cloudflare tunnel to 127.0.0.1:8770 — not a multi-tenant SaaS farm
Who can open jobsSole operator (Carroll Miller) while materials exist; you via pickup/retrieve; no contractor content farm
Encryption in transitHTTPS / TLS at Cloudflare
Encryption at restNot advertised as FDE. Job files live on local plant disk under OS permissions. No customer-managed keys.
Backups of your pileNone intentional as a product feature
PurgeReady 72h if not downloaded; ~30 min after first ZIP download; fail 24h — job dir + brick + export ZIP
Doc content in logs?Not by design as full-text logging; see § Logs
Breach targetNotify affected customers without unreasonable delay (pilot commitment)

1. Hosting & network path

2. Who can access jobs

Longer form: Privacy §5.2.

3. Encryption

4. Deletion mechanics (purge)

A purge loop on the plant (default about every 15 minutes) deletes expired jobs under the hopper work root:

After a successful build, inbox upload copies are cleared early; the brick/ZIP remain until purge. Ready jobs: 72h if never downloaded; about 30 minutes after the first successful ZIP download (each download refreshes that grace). Failed jobs target 24h.

Short-lived classify/Go staging directories under the OS temp area are removed in a finally path after the request — they are not a second archive.

4.1 Systems that may still hold something

SystemExists on this door?Max retention we stand behind
Customer-job backups / snapshots (product)No intentional featureN/A — we do not run a “restore your pile” backup product
Plant job materialsYesUntil purge clock (72h Ready if not downloaded; ~30 min after first ZIP download; 24h fail), then deleted under work root
OS crash dumps / swap remnantsPossible on any real machineNot controlled by the purge daemon; we do not claim crypto-wipe
Cloudflare edge / security logsYes (provider)Per Cloudflare retention — outside our purge; typically connection metadata, not a PDF archive
Stripe payment recordsYesPer Stripe + our ledger needs (accounting / disputes) — not document corpus
Operational server / plant logsYesShort ops window unless abuse or incident investigation
Optional Ready-notify queueMay exist if you opt inEmail + minimal ready signal — not the corpus; mill can run without sending mail

Detail twin: Privacy §5.1.

5. Subprocessors (pinned)

ProviderRoleCan uploaded document content reach them?
Cloudflare, Inc. DNS, CDN, TLS, tunnel, bot/DDoS basics In transit only as HTTPS bytes pass the edge — not retained by us as a document store. We do not use Cloudflare as object storage for your pile.
Stripe, Inc. Checkout, authorize / capture / void, tax tools when configured No — payment data, not your PDFs
Operator plant (KBMill) Manufacture, job store, purge, ledger files Yes — that is the processing location
Ready-notify SMTP / webhook Optional email/webhook if enabled No corpus in the notify payload by design; address + ready signal only if wired

Default public mill path does not ship your PDFs to a separate third-party “document SaaS.” If remote GPU workers are ever used for customer jobs on this door, they will be named here before that happens.

6. Logs, tickets, and “improve the plant”

Operational signals we may retain (not as a hosted knowledge base):

We do not, by design, keep a debugging corpus of:

While a job is alive, extracted text / OCR / embeddings exist as part of manufacture under the job/brick directories — then fall under purge. Operator email threads you start may quote what you paste; don’t paste secrets into email.

7. Host controls (honest list)

Not claimed: SOC 2, ISO 27001, published vuln-scan SLA, pentest certificates on a calendar, 24/7 SOC, MDM attestation, or universal MFA proof for every dependency.

8. Breach-notification target

If we become aware of unauthorized access to your mill uploads or job materials, we aim to notify affected customers without unreasonable delay (email on file and/or site notice). Pilot commitment — not liquidated damages. Enterprise timelines belong in a signed agreement.

9. Accountability contact

Carroll Miller, d/b/a KBMill
Email (privacy, security, signed-path): [email protected]
Web: https://kbmill.com
No public mailing address on this pilot page; email is the notice / contact channel. US-centered service — see Privacy international note (not a GDPR compliance claim).

10. When this page is not enough

Ordinary / public technical documents in a short-lived pilot: this page + Privacy + Terms are meant to be credible and candid. Trade secrets, personal/regulated records, or contractual confidentiality: get a signed DPA / security schedule first — or keep processing on machines you control.