What happens when you upload
- Your document travels over encrypted connections (HTTPS/TLS) and is stored with server-side encryption (AWS S3).
- Your account and session are protected by Firebase Authentication; your analyses are yours, tied to your account.
- The analysis runs for you — the output is a private report in your dashboard, not content shown to anyone else.
Why you can check the AI's work
- Every finding cites its source. Risk flags quote the exact clause from your document, so you can verify each one in seconds.
- Confidence is shown, not hidden. When Main AI is less certain about a document's type, it says so — right on the analysis and in the exported report.
- Facts and judgment are separated. Reports distinguish what the document says from what we recommend you do about it, and always include a "verify with a human" section.
What Main AI will never pretend to be
Main AI is document intelligence, not a law firm, medical provider, or financial advisor. It prepares you to act — organized facts, deadlines, drafts, and questions worth asking a professional — and is explicit about where a professional should take over. High-stakes decisions deserve both: a fast, thorough first read and qualified human judgment.
Security controls you can verify yourself
These are enforced at the transport layer on every response — you can confirm them with your browser's network inspector or a tool like curl -I.
- HTTPS is enforced. Strict-Transport-Security is set for two years with
includeSubDomains; preload, and insecure requests are upgraded automatically. - The site can't be framed.
X-Frame-Options: SAMEORIGINplus a CSPframe-ancestors 'self'block clickjacking. - A strict Content-Security-Policy limits what scripts and connections are allowed, with
object-src 'none'andbase-uri 'self'. - No MIME-sniffing, minimized referrers, and camera/microphone/geolocation disabled via
Permissions-Policy. - Card details never touch our servers — payments are handled by Stripe; authentication by Firebase.
What we don't claim
Trust is easier to give when a product is honest about its limits. Main AI does not claim formal security certifications (such as SOC 2 or ISO 27001), independent penetration-test attestations, or end-to-end encryption of document content beyond encryption in transit and at rest. If we ever earn those, we'll say so here — and only here, once it's true.
See it on your own document
The first scan is free and doesn't require an account. Upload something and check the citations yourself — that's the whole point.
Run a free document check →