Security & Data Handling

Revised: 9/10/2026


This page describes how CodeX Enterprises LLC (doing business as Biz Intelligence Champions) protects the data involved in using our products. It sits alongside our privacy policy, which tells you what we collect and why, and our terms. Where this page states a period or a commitment, it is drawn from an internal policy document we maintain and will share with enterprise customers on request.


1. THE MOST IMPORTANT THING: YOUR ROWS DO NOT LEAVE


LLM AI Charts generates chart code, and that code runs on your machine against your data. What our service receives is the measured shape of your data — column names, data types and aggregate statistics such as distinct counts, blanks, minimum, maximum, mean and standard deviation. Your cell values and your rows are not transmitted, to us or to any AI provider.


There are two narrow, deliberate exceptions, so that a chart can label and order itself correctly: where a column's values match a recognised ordered scale, that list of labels is sent so the axis is not drawn alphabetically; and where a non-text column is used as a category — a year, a true/false, a date — up to five of its most common values are sent. Neither carries a measure, a row, or the contents of a text column.


You can see exactly this before you send it. Both the Excel add-in and the Power BI visual have a "See what's sent" panel that shows the precise payload for your data, in full, before any generation happens. We would rather you checked than took our word for it.


2. WHERE YOUR DATA IS STORED


Your account, licence and usage records and our operational logs are held in Microsoft Azure in the United States (US West regions). Our infrastructure is entirely platform-as-a-service — managed Azure App Service, Azure SQL Database, Azure Storage and Azure Key Vault. We operate no virtual machines, which removes an entire class of patching and hardening risk from the picture.


3. ENCRYPTION


  • In transit: TLS 1.2 or higher, enforced. TLS 1.0 and 1.1 are refused.
  • At rest: Azure Storage and Azure SQL encryption at rest, on all data.
  • Bring-your-own AI keys: if you connect your own OpenAI, Azure OpenAI or Anthropic account, that key is encrypted at rest and used only to call your provider on your behalf.
  • Deployment: FTPS-only; there is no plaintext deployment path to our service.
  • Passwords: stored hashed and salted, never recoverable. Multi-factor authentication, including authenticator apps and passkeys, is available on your account.

4. WHAT WE KEEP, AND FOR HOW LONG


  • Account, licence and credit records — for the life of your account. Financial records are kept for 7 years, as the law requires.
  • Generation logs (the prompt we build, the model's response, the generated code, your column names and data types, timings, outcome and errors) — 24 months. We keep them this long because they are how we measure whether a change to our engine would take a working chart away from someone.
  • Client diagnostics — 12 months.
  • Chart thumbnails (Power BI visual; off by default) — deleted with the chart or the account.

Deleting your account is self-service and removes your account record immediately. One honest caveat we would rather state than gloss: data removed from our live database persists in point-in-time database backups until that backup window passes, after which it is gone. To correct your data, or to ask us to restrict how we process it, write to info@bizintelligencechampions.com.


5. WHO ELSE IS INVOLVED


Our sub-processors, and what each one receives:

  • Microsoft Azure — hosting, database, storage, and (for some models) AI inference. Prompts sent to Azure AI Foundry models are not used to train models and are reviewed by Microsoft only under abuse investigation.
  • Anthropic — AI inference for our default models, under Anthropic's commercial terms. Prompts are not used for training.
  • Stripe — payment processing. Card details are entered on Stripe's own pages and never reach our servers; we hold only transaction identifiers and amounts.

If you connect your own AI provider account, your requests go to that provider under your contract with them, and their data-handling terms apply instead of ours.


6. HOW WE CONTROL ACCESS


  • Multi-factor authentication is required on every administrative account — source control, DNS, cloud, payments and AI provider accounts.
  • Secrets live in Azure Key Vault and protected application configuration, never in source code. This is enforced by an automated test that fails our build if a credential-shaped value appears anywhere in the codebase.
  • Database access is restricted by an explicit network allow-list; the database is not reachable from the open internet.
  • Access is granted at the minimum needed, reviewed annually, and revoked within 24 hours when someone's involvement ends.

7. IF SOMETHING GOES WRONG


We maintain a written incident response plan with defined severities, a containment-first first hour, and evidence preservation before cleanup.


If a security incident affects personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and affected individuals without undue delay where the risk to them is high. We will do this on an incomplete investigation rather than miss the window.


For continuity, our target is to lose no more than 1 hour of data and to restore service within 8 hours in a serious failure — considerably faster for the common case, where we roll back to the previous known-good build in minutes. Database point-in-time restore runs continuously, and every build we deploy remains available to roll back to.


Worth knowing, because it is a genuine advantage of how this product works: a chart we have already generated for you keeps working if our service is down. It is saved in your own workbook or report and redraws from there without calling us.


8. FOUND A VULNERABILITY?


Please tell us at info@bizintelligencechampions.com with enough detail to reproduce it. We will acknowledge you, assess it, and keep you informed. We will not pursue anyone who reports a genuine issue to us in good faith and gives us a reasonable opportunity to fix it before disclosing it. Please do not access, modify or delete data that is not yours while investigating.


We rank findings by exploitability against our production service rather than by score alone, and we remediate critical issues within 7 days — mitigating within 24 hours where a full fix takes longer.


9. WHAT WE DO NOT CLAIM


We would rather be straight with you than imply more than we have. We do not hold SOC 2, ISO 27001 or FedRAMP certification, and we do not claim HIPAA, PCI DSS or HITRUST compliance. We are a small, focused engineering company, and those programmes carry a cost structure we have not taken on.


What we offer instead is the thing those programmes are meant to give you evidence of: an architecture where your data does not come to us in the first place, a written set of security and privacy policies we will share with you, and a service you can verify for yourself — the "See what's sent" panel shows you our data handling directly, rather than describing it.


Our products are not intended for personally identifiable information, classified information, or regulated data such as protected health information or payment card data. Please avoid or obfuscate such fields before they enter a dataset you point our products at.


10. QUESTIONS


Security, privacy and compliance questions all go to info@bizintelligencechampions.com. If your organisation needs our underlying policy documents, a data processing agreement, or answers to a security questionnaire, ask — we would rather answer than have you guess.

This application may no longer respond until reloaded. Reload 🗙