Trust center

Security, privacy, and compliance documentation.

Financial reports are sensitive. We treat them that way: with EU-region primary processing for filing data, encrypted storage, a published sub-processor list, and clear documentation on what we do and don't do with your data.

Hosting

EU processing for filing data

Hosting, database storage, document persistence, OCR, and AI document processing run in EU regions for filing data — model inference uses OpenRouter's EU data-region endpoint. The sub-processor list identifies each provider and location; the DPA describes the applicable approval and transfer safeguards.

Encryption

AES-256 at rest, TLS 1.2+ in transit

Each source document is encrypted inside the application before it reaches storage, under its own key from AWS KMS in the EU. That key is bound to that one document, so its ciphertext is meaningless anywhere else.

Sub-processors

Published cloud and AI providers

The current sub-processor list is public and names each provider's role and processing location. Changes are handled under the notice and objection process in the DPA.

Access

Role-based access control

Role-based access (RBAC), with administrative activity recorded in an audit log scoped to your workspace. SSO/SAML is implemented for configured organizations; confirm domain and identity-provider setup during procurement.

Oversight

Human approval required

No filing leaves the platform without a reviewer's explicit approval. Suggestions are always editable and overridable.

GDPR & DPA

GDPR-oriented controls

The DPA, sub-processor list and security measures are public. Uploaded documents are deleted within 30 days of account deletion or contract termination, subject to limited backup, recovery and legal-retention exceptions.

Scope. Any audited security programs referenced apply to the relevant sub-processor's services and are not a certification of Doc2iXBRL itself. We will not claim coverage we do not have; the current state of our own controls is reviewed under NDA during procurement.

Revision. Version 1.0, last updated 12 August 2026. Changes to the statements on this page are tracked in the repository's history and are checked on every change by an automated date-and-version gate.

Incident response

GDPR Article 33 response process

We maintain a documented incident response process aligned with the GDPR Article 33 breach-notification requirements, including assessment, containment, and notification steps.

Read our incident response process
GDPR & DPA

Training use is restricted in the DPA.

The DPA prohibits using Customer Data to train or improve our own or third-party AI/ML models, except with the customer's specific prior written consent for a defined purpose.

Read the full security measures

Public documents.

Open buyer brief

Need provider-specific evidence or a tailored review package? Contact us with your review scope