Our cloud We run it. Upload a file and go. Sign in and paste - first result in about 30 seconds. | Your cloud The engine runs in your own AWS account. Documents never reach us. Work with a Petrarch engineer to get this set up. | Your machine The desktop app on hardware you own. No network needed. Availability depends on hardware specifications - contact lindo@petrarch.co to learn more. | |
|---|---|---|---|
| Where the documents sit | A managed Postgres service under Petrarch's account, encrypted at rest by its provider, who is named on the subprocessor list. Region is fixed per deployment; ask us in writing. | Your S3 buckets. They are never copied out of your account. | Your disk. Nothing is written anywhere else. |
| Who holds the encryption keys | The storage provider, under Petrarch's account. Customer-managed keys are not available in this model yet. | You. Your KMS key; we are granted decrypt on it and you can revoke that in one click. | You. There is no second party. |
| What we can see | The document content, while it processes. Support staff read it only under a grant you can see and revoke. Every read is written to your audit log before the text is returned, or refused with a 503. That log is API-only today. | Page counts, run durations, error types. No content. We could not produce your document if asked. | Nothing. Optional usage pings carry page counts and can be switched off. |
| If we were served a subpoena | We would have your documents for the retention window and would have to respond. | We would have nothing to hand over but metering records. | We would have nothing at all. |
| If we went out of business | You would need to export before the wind-down window closed. | The deployment keeps running. The licence converts to perpetual on the last shipped version. | Nothing changes. The app keeps working offline. |
| Data leaving your network | Yes - TLS 1.3 to our API. Documents cross the public internet. | No. The engine runs beside your data, inside your own network. | No. |
| Retention | Input TEXT deleted 7 days after you certify a run. Files and outputs when you delete them. | Whatever your bucket lifecycle says. We set nothing. | Whatever you do. |
| Compliance posture | SOC 2 readiness work is in progress; no Type II report has been issued. GDPR processor terms on request. The sub-processor list is published, including the parties we could not pin down. | Inherits your posture. We are not a processor of content in this model. | Inherits your posture entirely. |
| Time to first result | About 30 seconds. Sign in and paste. | 2 to 5 days once the module exists: a Terraform apply and one security review your side. It does not exist yet, so a date comes after the scoping call. | 20 minutes: download, install, first model load. |
| Throughput on 100,000 pages | About 2.5 hours. We scale it out. | Same, on instances you pay AWS for directly. | About 40 hours on one M2 Pro. Parallelise it yourself. |
| What it costs | Included. We cover the processing cost, whatever the page count. | Quoted per deployment, plus your own AWS bill. No per-page charge. | Per-seat licence from $1,200 a year. No per-page charge. |
| Who operates it | Us. Upgrades, models and incidents are ours. | Shared: we ship the module and the images, you apply them. | You. |
| Best when | You are evaluating, the corpus is not the crown jewels, or you need it today. | Your data cannot leave your account but you want the throughput and the hosted UI. | The material is regulated, air-gapped, or under a contract that forbids third-party processing. |
| Start here | Request setup | Get the app |