We are not zero knowledge.
The application must read documents to extract useful details. Anyone claiming both server side AI extraction and a service that can never read your documents is describing incompatible things.
We do not claim end to end encryption.
Our chosen boundary is encryption before storage under application controlled keys. That protects against storage credential and bucket failures, but not a compromised application server.
We do not claim a certification we have not earned.
Compliance language will name its scope, evidence, and review date. A badge is not a substitute for a control that works.