Foxit AI Assistant
Security Overview
This overview describes the principal security, privacy, architecture, and data-handling characteristics of Foxit AI Assistant in PDF Editor, integrated Editor AI features, and Foxit Workspace. It is intended for customer technical and security review.
Feature availability and processing paths vary by release, platform, location, account, configuration, and entitlement. Where this overview conflicts with any applicable customer agreement, data processing agreement, privacy notice, subprocessor disclosure, or product-specific documentation, the latter shall control.
At a glance
- User-directed processing: Content is processed when a user selects, uploads, references, or otherwise provides it to an enabled feature.
- Purpose limitation: Foxit does not—and does not authorize or instruct its subprocessors to—use customer documents, prompts, AI outputs, or other customer content to train or fine-tune AI or machine learning models unless the customer expressly authorizes that use.
- Processing choices: Eligible Editor workflows can use Cloud mode, On-Device mode with Local SLMs, or Custom mode with a customer-configured endpoint. Foxit Workspace is available through cloud-connected client experiences, including the Workspace desktop application. While users can manage Projects, Sources, and Artifacts through these clients, AI processing is performed through cloud services and On-Device processing is not supported for Workspace.
- Data minimization: Workflows use the content and context reasonably needed to complete the user's request.
- Human control: Users should review AI-generated output before relying on or applying it, particularly in high-impact contexts. Users are solely responsible for their reliance on or use of the AI-generated output.
- Security controls: Depending on the processing path, Foxit applies encrypted transport, access controls, logical separation, user approvals, provider review, and retention controls.
Product overview
Foxit AI Assistant includes the following product areas:
- AI Assistant in Editor — the AI experience available within Foxit PDF Editor, including AI Chat and document-focused AI capabilities.
- AI Assistant tab capabilities — AI-enabled capabilities available from the AI Assistant tab in Foxit PDF Editor, including AI Chat, AI Bookmark, Translate Document, Read Aloud, Smart Podcast, and formula recognition / MathML generation.
- Foxit Workspace — a project-based AI workspace, separate from the Editor, for multi-document AI work and supported Connectors.
AI Assistant in Editor
AI Assistant in Editor enables users to interact with AI in the Foxit PDF Editor environment. AI Chat lets users chat with the AI about the open PDF or ask general questions. Other supported workflows can include summarization, rewriting, Translate Document, writing assistance, AI Bookmark, Read Aloud, Smart Podcast, and related AI Assistant tab capabilities.
The following profile summarizes the current AI Assistant capabilities in Foxit PDF Editor. Availability depends on the applicable release, platform, account, model configuration, and entitlement.
- Capability group
- Document chat and text assistance
- Current product scope
- Document Q&A, summaries, rewriting, translation assistance, and related text workflows across supported Editor experiences
- Cloud AI
- Yes
- Local SLMs
- Supported for eligible desktop workflows
- Custom
- Supported for eligible desktop workflows
- Material processing or availability note
- Local AI availability depends on the device, model, and supported workflow.
- Capability group
- Translate Document
- Current product scope
- Windows, macOS, and Editor Cloud, subject to applicable release and entitlement
- Cloud AI
- Yes
- Local SLMs
- Yes on supported desktop configurations
- Custom
- Yes on supported desktop configurations
- Material processing or availability note
- Processing varies by platform and document content.
- Capability group
- AI Bookmark
- Current product scope
- Windows, macOS, Editor Cloud, and Mobile
- Cloud AI
- Yes
- Local SLMs
- Yes on supported desktop configurations
- Custom
- Yes on supported desktop configurations
- Material processing or availability note
- OCR documents may require a cloud document-analysis path. Mobile uses an uploaded processing path.
- Capability group
- Read Aloud and Smart Podcast
- Current product scope
- Read Aloud is supported across eligible Editor experiences; Smart Podcast is a separate Windows and macOS experience where supported
- Cloud AI
- Yes
- Local SLMs
- No
- Custom
- No
- Material processing or availability note
- Audio processing is feature- and platform-specific.
- Capability group
- Agentic and tool-enabled workflows
- Current product scope
- Natural-language PDF actions, diagram creation, Skills, and supported Connectors on eligible desktop releases
- Cloud AI
- Yes
- Local SLMs
- No
- Custom
- Supported when the configured model and endpoint provide the required tool capabilities
- Material processing or availability note
- Consequential document actions can require user review or confirmation.
- Capability group
- Vision-enabled workflows
- Current product scope
- Formula recognition, MathML generation, and supported image-understanding actions
- Cloud AI
- Yes
- Local SLMs
- No
- Custom
- Supported when the configured model provides the required vision capabilities
- Material processing or availability note
- Platform and file support are release-specific.
- Capability group
- Cloud-only services
- Current product scope
- Image generation, web search, and other services identified as cloud-only in the applicable release
- Cloud AI
- Yes
- Local SLMs
- No
- Custom
- No
- Material processing or availability note
- External-service processing applies when the user invokes the capability.
| Capability group | Current product scope | Cloud AI | Local SLMs | Custom | Material processing or availability note |
|---|---|---|---|---|---|
| Document chat and text assistance | Document Q&A, summaries, rewriting, translation assistance, and related text workflows across supported Editor experiences | Yes | Supported for eligible desktop workflows | Supported for eligible desktop workflows | Local AI availability depends on the device, model, and supported workflow. |
| Translate Document | Windows, macOS, and Editor Cloud, subject to applicable release and entitlement | Yes | Yes on supported desktop configurations | Yes on supported desktop configurations | Processing varies by platform and document content. |
| AI Bookmark | Windows, macOS, Editor Cloud, and Mobile | Yes | Yes on supported desktop configurations | Yes on supported desktop configurations | OCR documents may require a cloud document-analysis path. Mobile uses an uploaded processing path. |
| Read Aloud and Smart Podcast | Read Aloud is supported across eligible Editor experiences; Smart Podcast is a separate Windows and macOS experience where supported | Yes | No | No | Audio processing is feature- and platform-specific. |
| Agentic and tool-enabled workflows | Natural-language PDF actions, diagram creation, Skills, and supported Connectors on eligible desktop releases | Yes | No | Supported when the configured model and endpoint provide the required tool capabilities | Consequential document actions can require user review or confirmation. |
| Vision-enabled workflows | Formula recognition, MathML generation, and supported image-understanding actions | Yes | No | Supported when the configured model provides the required vision capabilities | Platform and file support are release-specific. |
| Cloud-only services | Image generation, web search, and other services identified as cloud-only in the applicable release | Yes | No | No | External-service processing applies when the user invokes the capability. |
Cloud, On-Device, Custom, and Local SLM availability depend on the applicable release, platform, account, configuration, and entitlement.
Integrated Editor feature notes
Processing for AI Assistant tab capabilities depends on the feature, platform, document type, and selected mode. Availability of Cloud, On-Device, and Custom processing for major Editor capabilities is summarized in the current capability profile above.
Foxit Workspace
Foxit Workspace is a project-based AI workspace, separate from the Editor, built for multi-document AI creation, knowledge work, document analysis, AI-assisted content creation, artifact generation, and Connectors. Foxit Workspace organizes work into Projects. Each Project can contain Sources, chat sessions, generated Artifacts, and Project Context. User Memory, Instructions, Skills, Connectors, and general preferences are user- or Workspace-level configuration and can be used across Projects when enabled or configured.
Core Workspace capabilities can include source management and retrieval, AI chat and content generation, artifact creation and editing, and optional web search, Skills, and Connectors where supported.
Processing modes
Foxit AI Assistant has different processing boundaries depending on product area and configured mode:
- Product area
- AI Assistant in Editor
- Processing mode
- Foxit PDF Editor AI Assistant — cloud processing mode
- Scope
- Cloud-supported Editor AI capabilities are processed through the applicable Foxit-managed cloud workflow.
- Product area
- AI Assistant in Editor
- Processing mode
- AI Assistant in Editor — On-Device mode with Local SLMs or Custom mode
- Scope
- Document processing and product-side data storage are local; Custom mode model requests go to the user-configured external service.
- Product area
- AI Assistant tab capabilities and feature-specific Editor workflows
- Processing mode
- Cloud mode, On-Device mode, Custom mode, or feature-specific path
- Scope
- Processing mode depends on the individual feature, platform, document type, and applicable product configuration.
- Product area
- Foxit Workspace
- Processing mode
- Workspace cloud processing mode
- Scope
- Workspace operates through cloud-connected services and does not support On-Device processing.
| Product area | Processing mode | Scope |
|---|---|---|
| AI Assistant in Editor | Foxit PDF Editor AI Assistant — cloud processing mode | Cloud-supported Editor AI capabilities are processed through the applicable Foxit-managed cloud workflow. |
| AI Assistant in Editor | AI Assistant in Editor — On-Device mode with Local SLMs or Custom mode | Document processing and product-side data storage are local; Custom mode model requests go to the user-configured external service. |
| AI Assistant tab capabilities and feature-specific Editor workflows | Cloud mode, On-Device mode, Custom mode, or feature-specific path | Processing mode depends on the individual feature, platform, document type, and applicable product configuration. |
| Foxit Workspace | Workspace cloud processing mode | Workspace operates through cloud-connected services and does not support On-Device processing. |
On-Device mode and Custom mode are processing modes rather than product names. In supported On-Device workflows, document processing, product-side storage, and model inference occur on the user's device. In Custom mode, Foxit product-side document processing and storage remain local, while model requests are sent to the customer-configured external endpoint.
On-Device mode and Custom mode support the following configurations:
- Local SLMs: compatible small language models downloaded to and run on the user's device. Availability depends on device capability and the applicable product release.
- Custom: a user-configured, OpenAI-compatible external model service. Availability of tool- or vision-dependent features is determined by the capabilities of that model and endpoint.
Supported operating systems, models, local storage behavior, and feature compatibility are defined by the applicable product release and configuration.
Architecture and data flows
Foxit AI Assistant separates customer-controlled clients and local processing from Foxit-managed cloud services, Foxit service providers, and customer-selected services. The diagram shows logical trust and processing boundaries rather than physical network topology.
- Customer environment: Foxit client experiences, On-Device components, user settings, and customer-authorized credentials operate in the customer-controlled environment. In supported On-Device workflows, document processing, product-side context, storage, and Local SLM inference remain on the device.
- Foxit-managed service boundary: Cloud-supported features and Workspace can use Foxit-managed identity, access control, workflow orchestration, document processing, retrieval, and product data services.
- Foxit service providers: Foxit uses reviewed cloud, AI model, document-processing, infrastructure, and web-search services according to the feature and deployment configuration.
- Customer-selected third parties: Custom endpoints and customer-authorized connected services are selected and authorized by the customer. Their processing is governed by the customer's configuration and the third party's terms and controls.
Each workflow uses only the components required by the selected product, feature, platform, processing mode, and customer configuration.
Editor processing paths
The following data flows show how document content and user input are handled by AI Assistant in Foxit PDF Editor and by integrated Editor features. A workflow may use only the steps and services required for the selected feature.
Cloud processing mode
- The user invokes an AI capability and selects or provides the content needed for the task.
- The Editor prepares the prompt, relevant document content, and request context.
- The request is transmitted to Foxit-managed services, where identity, entitlement, policy, document-processing, and orchestration controls are applied as appropriate.
- The applicable Foxit service provider processes the task and returns the service output to Foxit.
- Foxit prepares the response, source references, or feature result and returns it to the Editor for user review or application.
Boundary: Selected input and relevant document content leave the device and are processed through the applicable cloud workflow.
On-Device mode with Local SLMs
- The user invokes a supported On-Device capability.
- Foxit PDF Editor and its On-Device components process the document and prepare task context on the device.
- A compatible device-resident model performs inference locally.
- The result is returned to the Editor for user review or application.
Boundary: Document processing, product-side context and storage, and model inference remain on the device for the supported workflow.
Custom mode
- The user or organization configures a supported external, OpenAI-compatible model endpoint.
- Foxit PDF Editor and its local processing components process the document and maintain product-side context locally.
- The model request required for the task is transmitted directly to the configured external endpoint.
- The external service returns the model output, which the Editor presents for user review or application.
Boundary: Product-side document processing and storage remain local, while the model request and response are processed by the customer-selected provider under the customer's configuration and that provider's terms.
Integrated and feature-specific processing
- The user invokes AI Bookmark, Translate Document, Read Aloud, Smart Podcast, or another integrated capability.
- The Editor determines the applicable path based on the feature, platform, document type, and configured mode.
- Supported desktop workflows can process document content locally. Where cloud document analysis, speech, model, or other services are required, the content needed for that task is sent through the applicable cloud path.
- The resulting bookmarks, translated content, audio, or other feature output is returned to the Editor.
Boundary: The processing boundary is feature-specific. AI Bookmark for OCR documents may use a cloud document-analysis service, and supported Mobile workflows use an uploaded processing path.
Workspace processing path
The Workspace diagram distinguishes Project content from user- or Workspace-level configuration and shows the separate path for customer-authorized external services.
Workspace request flow
The following diagram shows how a typical Workspace request moves from user input and selected Sources through access validation, context assembly, and applicable service processing to a response or artifact. When a task requires a client tool or connected service, it follows a separate configuration and approval path through Connectors.
- The user adds source material or enters a request in a Workspace Project.
- Foxit Workspace stores Project content and, where needed, processes documents into searchable or retrievable representations.
- Workspace assembles the request from the current session, selected Sources, Project Context, enabled Skills, and available tools.
- The applicable model, document-processing, web-search, or other service performs the requested task. Client-side or third-party tools are invoked only through the applicable connector and approval flow.
- Workspace returns the response or generated artifact and associates retained content with the Project according to the applicable product controls.
Boundary: Workspace is a cloud service. Project content is processed and stored within the applicable Foxit-managed service boundary, with task-specific transfers to Foxit service providers or customer-authorized external tools where required.
Responsibility boundaries
- Processing relationship
- Foxit-managed cloud workflow
- Foxit responsibility
- Operate the Foxit product boundary; apply applicable access, security, provider-management, and data-handling controls; and deliver the requested product function.
- Customer or third-party responsibility
- Configure and use the product appropriately; control authorized users; determine whether submitted content is permitted; and review AI output.
- Processing relationship
- On-Device mode with Local SLMs
- Foxit responsibility
- Provide the supported product capability and local processing integration.
- Customer or third-party responsibility
- Secure the device and local account, manage locally stored data, and verify model output.
- Processing relationship
- Custom mode
- Foxit responsibility
- Keep supported Foxit product-side document processing and storage local and transmit the model request to the configured endpoint.
- Customer or third-party responsibility
- Select, configure, secure, and contract with the model provider; manage credentials and retention settings; and assess the provider's processing terms.
- Processing relationship
- Connector or other customer-connected service
- Foxit responsibility
- Provide supported connector controls, tool visibility, and applicable approval mechanisms.
- Customer or third-party responsibility
- Authorize the service and scopes, assess the connected provider, approve requested actions, and manage data after it reaches that provider.
| Processing relationship | Foxit responsibility | Customer or third-party responsibility |
|---|---|---|
| Foxit-managed cloud workflow | Operate the Foxit product boundary; apply applicable access, security, provider-management, and data-handling controls; and deliver the requested product function. | Configure and use the product appropriately; control authorized users; determine whether submitted content is permitted; and review AI output. |
| On-Device mode with Local SLMs | Provide the supported product capability and local processing integration. | Secure the device and local account, manage locally stored data, and verify model output. |
| Custom mode | Keep supported Foxit product-side document processing and storage local and transmit the model request to the configured endpoint. | Select, configure, secure, and contract with the model provider; manage credentials and retention settings; and assess the provider's processing terms. |
| Connector or other customer-connected service | Provide supported connector controls, tool visibility, and applicable approval mechanisms. | Authorize the service and scopes, assess the connected provider, approve requested actions, and manage data after it reaches that provider. |
Data handling
Foxit AI Assistant processes data according to the capability the user invokes. The following categories describe the current product baseline; a particular workflow may use only a subset.
- Data category
- Account and entitlement data
- Examples
- Account identifiers, organization identifiers, account email, subscription status, and entitlement
- Primary purpose
- Authenticate users, authorize access, administer subscriptions, and enforce applicable product and usage limits.
- Data category
- User-submitted content
- Examples
- Prompts, selected text, uploaded documents, images, and Project or integration content
- Primary purpose
- Perform the AI, document-processing, search, editing, translation, audio, or other tasks requested by the user.
- Data category
- AI inputs and outputs
- Examples
- Prepared request context, relevant document segments, generated responses, source references, and feature results
- Primary purpose
- Generate and return requested results and maintain the active workflow.
- Data category
- Workspace Project content
- Examples
- Sources, Project Chats, Artifacts, Project Context, and applicable sharing metadata
- Primary purpose
- Preserve and operate the user's Project-based Workspace experience.
- Data category
- Workspace-level configuration
- Examples
- User Memory, Instructions, Skills, Connectors, settings, and preferences
- Primary purpose
- Provide cross-Project personalization, reusable capabilities, and external-service configuration.
- Data category
- Tool and connector data
- Examples
- Tool requests and results, web-search queries, connector metadata, and Connector or Custom endpoint data
- Primary purpose
- Execute user-requested searches, tool calls, external model requests, or connected-service actions.
- Data category
- Operational and usage data
- Examples
- Service events, usage and credit information, security signals, diagnostics, and resource-consumption metadata
- Primary purpose
- Operate, secure, support, administer, and improve the service, subject to applicable settings, notices, and agreements.
| Data category | Examples | Primary purpose |
|---|---|---|
| Account and entitlement data | Account identifiers, organization identifiers, account email, subscription status, and entitlement | Authenticate users, authorize access, administer subscriptions, and enforce applicable product and usage limits. |
| User-submitted content | Prompts, selected text, uploaded documents, images, and Project or integration content | Perform the AI, document-processing, search, editing, translation, audio, or other tasks requested by the user. |
| AI inputs and outputs | Prepared request context, relevant document segments, generated responses, source references, and feature results | Generate and return requested results and maintain the active workflow. |
| Workspace Project content | Sources, Project Chats, Artifacts, Project Context, and applicable sharing metadata | Preserve and operate the user's Project-based Workspace experience. |
| Workspace-level configuration | User Memory, Instructions, Skills, Connectors, settings, and preferences | Provide cross-Project personalization, reusable capabilities, and external-service configuration. |
| Tool and connector data | Tool requests and results, web-search queries, connector metadata, and Connector or Custom endpoint data | Execute user-requested searches, tool calls, external model requests, or connected-service actions. |
| Operational and usage data | Service events, usage and credit information, security signals, diagnostics, and resource-consumption metadata | Operate, secure, support, administer, and improve the service, subject to applicable settings, notices, and agreements. |
Foxit AI Assistant is user-initiated: document content is processed only when a user selects, uploads, references, or otherwise provides it to an enabled capability. The amount and type of content processed depend on the task and processing mode. Users should not submit personal, confidential, regulated, or other sensitive information unless their organization permits the intended processing path.
Data lifecycle
- Processing mode or data class
- PDF Editor AI Assistant — Cloud processing mode request data
- Typical handling
- Selected prompts, relevant document content, and generated results are processed through the applicable Foxit-managed cloud workflow.
- Retention control
- Temporary processing lifecycle; the exact interval is defined by applicable product, privacy, contractual, or deployment-specific documentation.
- Processing mode or data class
- PDF Editor AI Assistant — On-Device mode with Local SLMs
- Typical handling
- Supported document processing, product-side context and storage, and model inference occur on the device.
- Retention control
- Controlled by the local product, device, and customer-managed environment.
- Processing mode or data class
- PDF Editor AI Assistant — Custom mode
- Typical handling
- Foxit product-side document processing and storage remain local; model requests and responses are handled by the configured external endpoint.
- Retention control
- Local data follows the product and device lifecycle. Retention of requests and responses processed by the external endpoint is governed by the customer's configuration and the provider's terms.
- Processing mode or data class
- Workspace Project content
- Typical handling
- Sources, Project Chats, Artifacts, Project Context, and related Project data are stored to maintain the Project experience.
- Retention control
- Retained until the user deletes the relevant content, the Project, Workspace, or account is deleted, or an applicable enterprise policy triggers deletion.
- Processing mode or data class
- Workspace-level configuration
- Typical handling
- User Memory, Instructions, Skills, Connectors, and general preferences are associated with the user's Workspace experience and can be used across Projects.
- Retention control
- Retained until the user deletes or resets the relevant configuration, the Workspace or account is deleted, or an applicable policy triggers cleanup.
- Processing mode or data class
- Workspace temporary processing data
- Typical handling
- Working files, tool results, previews, caches, and execution state support active workflows.
- Retention control
- Removed under the applicable temporary-data and service lifecycle.
- Processing mode or data class
- Operational and compliance records
- Typical handling
- Limited service, security, support, billing, fraud-prevention, or legal records.
- Retention control
- Retained according to applicable operational, legal, contractual, and security requirements.
| Processing mode or data class | Typical handling | Retention control |
|---|---|---|
| PDF Editor AI Assistant — Cloud processing mode request data | Selected prompts, relevant document content, and generated results are processed through the applicable Foxit-managed cloud workflow. | Temporary processing lifecycle; the exact interval is defined by applicable product, privacy, contractual, or deployment-specific documentation. |
| PDF Editor AI Assistant — On-Device mode with Local SLMs | Supported document processing, product-side context and storage, and model inference occur on the device. | Controlled by the local product, device, and customer-managed environment. |
| PDF Editor AI Assistant — Custom mode | Foxit product-side document processing and storage remain local; model requests and responses are handled by the configured external endpoint. | Local data follows the product and device lifecycle. Retention of requests and responses processed by the external endpoint is governed by the customer's configuration and the provider's terms. |
| Workspace Project content | Sources, Project Chats, Artifacts, Project Context, and related Project data are stored to maintain the Project experience. | Retained until the user deletes the relevant content, the Project, Workspace, or account is deleted, or an applicable enterprise policy triggers deletion. |
| Workspace-level configuration | User Memory, Instructions, Skills, Connectors, and general preferences are associated with the user's Workspace experience and can be used across Projects. | Retained until the user deletes or resets the relevant configuration, the Workspace or account is deleted, or an applicable policy triggers cleanup. |
| Workspace temporary processing data | Working files, tool results, previews, caches, and execution state support active workflows. | Removed under the applicable temporary-data and service lifecycle. |
| Operational and compliance records | Limited service, security, support, billing, fraud-prevention, or legal records. | Retained according to applicable operational, legal, contractual, and security requirements. |
Workspace-derived data is scoped to the content from which it is created. Parsed document representations, retrieval indexes, embeddings, chunks, and similar processing artifacts remain associated with their originating Source and Project. When a Source is deleted, associated derived data is removed through the applicable product process. When a Project is deleted, associated Project content and related derived data are removed through the applicable product process, subject to applicable backup, legal, security, and compliance retention requirements.
When a Project, Workspace, or account is deleted, associated primary content is removed through the applicable product process. Residual backup copies follow the backup lifecycle, and limited records may be retained where required for security, fraud prevention, legal obligations, dispute resolution, or contractual compliance.
Use of customer content
Foxit uses customer-submitted content to provide the capability requested by the user, such as document Q&A, summarization, translation, editing, retrieval, artifact creation, web-assisted research, or execution of an authorized tool workflow. Foxit does not, and will not authorize or instruct its subprocessors to, use customer documents, prompts, AI outputs, or other customer content submitted to or processed through the products on the customer's behalf to train or fine-tune any artificial intelligence or machine learning model, unless the customer has expressly authorized that use.
Product analytics and operational telemetry are separate from the substantive content of AI interactions. They are used to administer usage and entitlements, maintain service reliability, detect abuse or security events, provide support, and improve product operation in accordance with applicable settings, notices, and agreements.
Foxit AI Assistant does not intentionally require special-category, highly sensitive, or regulated personal data. Such information may nevertheless be present in documents or prompts submitted by users. Customers remain responsible for determining whether their intended content and processing path are permitted by applicable law, organizational policy, and contract.
Processing locations and international transfers
Foxit PDF Editor AI Assistant in Cloud processing mode and Foxit Workspace use Foxit Account for authentication and operate on the same regional Foxit cloud architecture. Available regional service instances may include the United States, Canada, Australia, the European Union, and Japan. Where regional deployment is supported, customer business data is routed to the customer's assigned regional instance and is logically isolated from business data in other regional instances. User's Foxit Account information, including email address and password, is currently stored in the United States, regardless of user location.
The two processing paths use the regional architecture differently:
- Foxit PDF Editor AI Assistant — Cloud processing mode: The user's prompt, the document content or context needed for the task, and the generated result are processed through the applicable regional cloud workflow. This request data is handled for the purpose of completing the user-requested task and follows the applicable temporary processing lifecycle.
- Foxit Workspace: Requests are processed through the same regional cloud architecture. Sources, Project Chats, Artifacts, Project Context, and related Project data are also stored in the customer's assigned regional instance according to the applicable retention controls.
Some features use third-party cloud, AI model, document-processing, or search services. Foxit uses regional service options where supported and appropriate, but not every provider or service is available in every Foxit region. If required processing occurs outside the assigned region, it is governed by applicable Foxit customer terms and Foxit's arrangements with that provider; provider region, endpoint, retention, and data-handling settings vary by service and configuration.
A globally available service or endpoint does not, by itself, mean that data remains in the customer's assigned region. Customers with specific data-residency or international-transfer requirements should refer to their agreement, data processing agreement, subprocessor disclosure, privacy notice, and deployment-specific documentation for the commitments applicable to their deployment.
For supported PDF Editor workflows, On-Device mode and Custom mode can reduce or avoid Foxit cloud processing:
- On-Device mode with Local SLMs: Supported document processing and model inference occur on the user's device.
- Custom mode: Foxit product-side document processing and storage remain on the device, but the model request and response are sent to the endpoint selected by the customer.
Foxit Workspace and capabilities that are available only through cloud processing require a cloud service path.
Workspace processing
Workspace processes Project content according to the architecture and request flow described above. Project content and related metadata are stored and processed within the applicable Project scope and assigned regional Workspace instance where supported. When Workspace uses model, document-processing, retrieval, web-search, or customer-authorized external services, it sends task-specific information reasonably needed for the requested function, subject to the customer's configuration, authorization, and applicable provider terms.
Security controls
Encryption and stored-data protection
Foxit uses encrypted network transport for authentication, cloud AI requests, Workspace traffic, content transfer, service integrations, and response delivery. Stored product data is protected through technical and organizational safeguards intended to limit access to authorized users, services, and personnel.
Workspace Project content is logically scoped to the authenticated account and applicable Project or sharing context. Persistent content, temporary working data, and user-visible outputs follow their applicable access scope and lifecycle.
Authentication and access control
Foxit Workspace uses Foxit account authentication for protected product functions. Access controls apply to Projects, sessions, sources, artifacts, sharing, and applicable client-tool data. Private Project content is made available only through the applicable authenticated and authorized product experience.
Connectors can use supported authorization methods or configured credentials. Third-party access is limited to the scopes and credentials authorized by the user or organization.
Authentication, access control, sharing, and enterprise administration options depend on the applicable product, account type, deployment, and customer agreement. Users and organizations are responsible for managing account access and any credentials they authorize for third-party services.
Permission and approval model
Foxit Workspace can require explicit user approval for sensitive or consequential operations, including selected client tool calls and Connector actions. Approval and tool availability depend on the client, connected service, authorized scopes, Project, account, and product configuration. Artifact changes can be presented for review before the revised output is retained.
Data minimization and telemetry
Foxit seeks to limit customer-content processing to information reasonably needed for the requested workflow. Product analytics and operational telemetry are limited to information used to administer entitlements and usage, operate and secure the service, diagnose problems, provide support, and improve product operation. Telemetry is governed by applicable settings, privacy notices, and agreements.
Third-party tools and connectors
Foxit AI Assistant supports controlled integration with local and third-party tools through Connectors in Foxit PDF Editor and Foxit Workspace Desktop. Connectors are explicitly configured, tool calls are surfaced in the product experience, and selected operations can require user approval. Access is limited by the OAuth scopes, API keys, or other credentials authorized by the user or organization.
Task-specific information is sent to the selected tool. Once data reaches a customer-authorized third-party service, that service is responsible for its processing, storage, security, and retention under the customer's authorization and the provider's terms. Users and organizations should review those terms and scopes before enabling a connector or approving a tool call.
Secure development practices
Foxit's development and release practices include security review, secure coding, code review, dependency management, vulnerability testing, release validation, and security monitoring, applied according to product risk and operating environment. Additional information about Foxit's secure development lifecycle and security engineering practices is available in the Foxit Development Security Overview.
AI output, content safety, and human review
Generative AI output can be incomplete, inaccurate, biased, or ungrounded. Foxit AI Assistant is designed as a productivity aid and not as a substitute for professional judgment or required human decision-making. Users should verify material outputs against the source document and other authoritative information before relying on them.
Foxit may apply input or output controls appropriate to the feature, model, and risk, including policy enforcement, restricted-use rules, content-safety controls, source references, user confirmations, and monitoring for abuse or security events. These controls may reduce risk but do not guarantee that every output will be accurate, appropriate, or safe for every use case. Customers are solely responsible for their reliance on any output of AI features/services provided by Foxit.
Foxit AI Assistant is not intended to make decisions about individuals that produce legal or similarly significant effects without meaningful human review. Customers are responsible for establishing appropriate review, authorization, and recordkeeping controls for high-impact workflows.
Privacy, terms, and provider information
Use of Foxit AI Assistant is governed by applicable Foxit product terms, privacy notices, data processing terms, customer agreements, and any other applicable documentation. Those documents determine the parties' privacy roles, applicable rights, and request processes for a particular deployment.
Third-party providers used in Foxit-managed workflows operate under applicable contractual and security controls. Customer-selected Custom endpoints, Connectors, and other integrations are governed by the customer's authorization and the third party's terms.
Provider information
Foxit AI Assistant and Foxit Workspace use reviewed service providers in Foxit-managed cloud workflows depending on the selected product, feature, processing mode, customer location, configuration, and deployment. The following table identifies the principal providers at a high level; applicable contractual commitments, subprocessor disclosures, processing locations, and data-processing terms are governed by the relevant customer agreement, data processing agreement, privacy notice, subprocessor disclosure, or deployment-specific documentation.
- Provider
- Microsoft Azure
- High-level use
- Managed AI model services and document-processing capabilities used by applicable Editor and Workspace workflows.
- Data involved when used
- Task-specific prompts, relevant document content or derived context, and service output required for the requested workflow.
- Provider
- Google Cloud Platform (GCP)
- High-level use
- Managed AI model services used by applicable Workspace workflows.
- Data involved when used
- Task-specific prompts, relevant source context, and generated model output.
- Provider
- Exa
- High-level use
- Web-search capabilities used when a user invokes a feature requiring current public-web information.
- Data involved when used
- Search queries and task context needed to retrieve and return relevant public-web results.
- Provider
- Amazon Web Services (AWS)
- High-level use
- Cloud infrastructure used to host applicable Foxit account, administration, Workspace services, storage, and operational data.
- Data involved when used
- Account and service data and, for Workspace, Project content and related operational data.
| Provider | High-level use | Data involved when used |
|---|---|---|
| Microsoft Azure | Managed AI model services and document-processing capabilities used by applicable Editor and Workspace workflows. | Task-specific prompts, relevant document content or derived context, and service output required for the requested workflow. |
| Google Cloud Platform (GCP) | Managed AI model services used by applicable Workspace workflows. | Task-specific prompts, relevant source context, and generated model output. |
| Exa | Web-search capabilities used when a user invokes a feature requiring current public-web information. | Search queries and task context needed to retrieve and return relevant public-web results. |
| Amazon Web Services (AWS) | Cloud infrastructure used to host applicable Foxit account, administration, Workspace services, storage, and operational data. | Account and service data and, for Workspace, Project content and related operational data. |
Foxit reviews providers through its security, privacy, legal, and vendor-management processes. Customer-selected Custom endpoints, Connectors, and other integrations are governed by the customer's authorization, configuration, and the applicable third party's terms.
Conclusion
Foxit AI Assistant combines Editor AI capabilities and Foxit Workspace within defined local, Foxit-managed cloud, provider, and customer-selected service boundaries. The applicable processing path determines where content is handled, what controls apply, and which party manages the service.
For more security information, visit Foxit Security Center and the Foxit Development Security Overview. Applicable customer agreements, data processing terms, privacy notices, subprocessor disclosures, and product documentation shall take precedence over this overview.