Understanding the complete data path helps you make informed decisions about what information you share. Here is the exact sequence of every document generation request:
claude-proxy.victoryhourdream.workers.dev). This proxy runs at Cloudflare's edge — it does not log request bodies, does not write data to any database, and processes each request in an isolated, stateless execution environment.SOP Command™ operates on a zero data retention architecture. This means:
What this means practically: If you entered your facility's proprietary chocolate formulation, your CFIA audit schedule, or your pharmaceutical batch parameters into SOP Command — that data does not exist on our systems the moment your browser session ends. We have nothing to disclose, share, or breach.
This is one of the most important commitments we make to regulated industry operators. We know your concern: "Will my facility's proprietary data be used to train an AI model that my competitors could benefit from?"
The answer is no. Here is why:
SOP Command™ is hosted on Cloudflare Pages and uses Cloudflare Workers as a serverless proxy layer. Cloudflare is one of the world's largest and most trusted network infrastructure providers, serving millions of websites and enterprise applications globally.
You can review Cloudflare's full security and compliance documentation, including their SOC 2 Type II certification and ISO 27001 compliance, at cloudflare.com/trust-hub.
We understand that pharmaceutical and GMP-regulated operators have heightened data sensitivity requirements. Your batch formulations, active pharmaceutical ingredient (API) concentrations, process validation parameters, and supplier qualification data represent significant commercial and regulatory assets.
Our specific commitments for GMP users:
Medical device manufacturers and their supply chains have specific requirements around data confidentiality, design history file protection, and complaint handling records. SOP Command™ is positioned as a support operations tool, not a Design History File (DHF) or Technical File system.
SOP Command™ uses the following third-party services. This is a complete and transparent list:
Role: Infrastructure provider. Does not access document content.
Role: Document generation. Does not store your operational data.
Role: Visual display only. No access to your data.
Role: Client-side processing only. No data transmitted to CDN.
We do not use: Google Analytics, Facebook Pixel, advertising networks, marketing tracking, session recording, or any behavioral analytics tools. We do not share data with data brokers, marketing companies, or industry databases.
In the event of a security incident affecting SOP Command™ infrastructure:
To report a suspected security vulnerability in SOP Command™, contact us immediately at info@victoryhourmedia.com with subject line "SECURITY — VULNERABILITY REPORT." We investigate all reports within 48 hours.
Security is a shared responsibility. As a user of SOP Command™, you are responsible for: