Skip to main content
Trust

Trust & security

Accessibility work means handling other people's documents, so we treat security as part of the product. Here's how we protect your data and what we're building toward — described honestly, without claiming certifications we don't yet hold.
1

Encryption

Your documents and data are encrypted in transit (TLS) and at rest. Downloads are streamed through authenticated endpoints rather than exposed as public links.

2

Tenant isolation & access control

Each account's data is logically isolated, and requests are authorized against the signed-in user so one customer cannot reach another's documents. Internal access is limited to authorized personnel on a least-privilege basis, with multi-factor authentication required for administrative access.

3

Data retention & deletion

We keep your documents only as long as your retention setting allows, and you can shorten that window. When it ends, files are deleted from active systems and residual backup copies age out on our normal cycle. We do not use your documents to train AI models.

4

Sub-processors

We rely on a small set of vetted infrastructure providers — hosting, storage, database, authentication, AI, and analytics — each bound by data-protection obligations. The current list is on our sub-processors page.

5

Privacy & data handling

We process your data only to provide the Service and never sell it. For the full picture — what we collect, how we use it, and your rights — see our Privacy Notice and Data Processing Addendum.

6

Compliance roadmap

We align our practices with GDPR and CCPA principles and are building toward formal third-party certifications as we grow. We don't claim certifications we haven't completed — when a report or attestation is issued, we'll say so here and share it with enterprise customers under NDA. The standard Service is intended for public-facing, non-sensitive documents and is not offered for protected health information.

7

Responsible disclosure

Found a security issue? We appreciate responsible disclosure. Email security@doccure.ai and we'll work with you on a fix. Please don't access other users' data or run disruptive tests against production.

doc cure · Trust & Security