Security & Compliance

Enterprise-grade security for your most sensitive questionnaire data

Security First

We understand that security questionnaires contain your company's most sensitive compliance and security information. Our platform is built with enterprise-grade security controls to protect your data at every stage.

Encryption

  • AES-256 encryption for data at rest
  • TLS 1.3 for data in transit
  • Encrypted backups with separate keys
  • End-to-end encryption for file uploads

Data Retention

  • Immediate deletion after processing
  • No long-term storage of documents
  • Maximum 15 minutes temporary storage
  • Secure deletion guaranteed

Access Controls

  • Password authentication with NextAuth
  • Bcrypt hashing for passwords
  • Session management with automatic timeout
  • Per-user isolation of data

Data Handling

  • Zero data retention by AI providers (Anthropic)
  • No training on your data
  • Isolated processing per user
  • Automatic file cleanup after processing

Security Measures

  • File type validation (magic bytes)
  • Size limits to prevent abuse
  • Path traversal prevention
  • Formula injection protection

Data Residency

  • EU-hosted infrastructure (Vercel, Neon)
  • GDPR compliant data processing
  • Standard Contractual Clauses (SCC)
  • Data Processing Agreement available

Sub-processors

ProviderServiceLocationData Processed
VercelHosting & CDNGlobal (EU available)Application hosting
NeonDatabaseEU (Frankfurt)User data, metadata
Anthropic (Claude)AI ProcessingUS (Zero retention)Document content (transient)
StripePayment ProcessingGlobalPayment information only
ResendEmailUSContact form submissions

All sub-processors are GDPR compliant and have signed Data Processing Agreements (DPA).

Compliance & Agreements

GDPR

Fully compliant with EU General Data Protection Regulation

✓ COMPLIANT

DPA Available

Data Processing Agreement available upon request

✓ AVAILABLE

SCC

Standard Contractual Clauses for international transfers

✓ AVAILABLE

Need More Security Details?

We're happy to complete your security questionnaire or provide additional documentation.