Security, privacy, and compliance documentation.
Financial reports are sensitive. We treat them that way: with EU-region primary processing for filing data, encrypted storage, a published sub-processor list, and clear documentation on what we do and don't do with your data.
EU processing for filing data
Hosting, database storage, document persistence, OCR, and AI document processing run in EU regions for filing data — model inference uses OpenRouter's EU data-region endpoint. The sub-processor list identifies each provider and location; the DPA describes the applicable approval and transfer safeguards.
AES-256 at rest, TLS 1.2+ in transit
Each source document is encrypted inside the application before it reaches storage, under its own key from AWS KMS in the EU. That key is bound to that one document, so its ciphertext is meaningless anywhere else.
Published cloud and AI providers
The current sub-processor list is public and names each provider's role and processing location. Changes are handled under the notice and objection process in the DPA.
Role-based access control
Role-based access (RBAC), with administrative activity recorded in an audit log scoped to your workspace. SSO/SAML is implemented for configured organizations; confirm domain and identity-provider setup during procurement.
Human approval required
No filing leaves the platform without a reviewer's explicit approval. Suggestions are always editable and overridable.
GDPR-oriented controls
The DPA, sub-processor list and security measures are public. Uploaded documents are deleted within 30 days of account deletion or contract termination, subject to limited backup, recovery and legal-retention exceptions.
Scope. Any audited security programs referenced apply to the relevant sub-processor's services and are not a certification of Doc2iXBRL itself. We will not claim coverage we do not have; the current state of our own controls is reviewed under NDA during procurement.
Revision. Version 1.0, last updated 12 August 2026. Changes to the statements on this page are tracked in the repository's history and are checked on every change by an automated date-and-version gate.
GDPR Article 33 response process
We maintain a documented incident response process aligned with the GDPR Article 33 breach-notification requirements, including assessment, containment, and notification steps.
Read our incident response processTraining use is restricted in the DPA.
The DPA prohibits using Customer Data to train or improve our own or third-party AI/ML models, except with the customer's specific prior written consent for a defined purpose.
Read the full security measuresPublic documents.
Need provider-specific evidence or a tailored review package? Contact us with your review scope