Your sensitive documents deserve enterprise-grade protection. We've built security into every layer of eScanX, from encryption and access controls to compliance and monitoring.
Multiple layers of security controls protect your data at every stage of processing
Your documents are encrypted in transit (TLS) and at rest throughout their lifecycle on our infrastructure.
Our infrastructure and processes are designed to meet SOC 2 Type II standards. We are actively working toward certification with independent third-party assessors.
We maintain strict compliance with GDPR, CCPA, and other international data protection regulations. Your data rights are protected wherever you operate.
Define precise access permissions for every team member. Control who can view, process, or export documents with granular role-based policies.
Key actions are recorded in an internal audit trail with detailed timestamps and user attribution, covering document access, API calls, and administrative changes.
Secure your integrations with robust API key management. Set expiration policies, restrict access by IP, and monitor usage patterns in real-time.
Built to the GDPR standard end-to-end. Data Processing Agreement available on request.
Inference and document storage run on EU-resident infrastructure. Sub-processors are listed in our privacy policy.
We do not send documents to external AI APIs (OpenAI, Anthropic, etc.). Extraction is performed on EU-resident compute.
Customer documents are never used to train or fine-tune our models. Your data stays yours.
Uploaded files are automatically deleted after a retention period in line with your plan; immediate deletion is available any time via the dashboard or API. See our Data Policy for exact retention windows.
A summary of how we handle your data. The full live breakdown — including regions, providers, and key management — is published at /policy.
We don't wait for vulnerabilities to find us. Our security team continuously tests, monitors, and improves our defenses to stay ahead of emerging threats.
We engage independent security firms for periodic penetration tests, simulating real-world attacks on our infrastructure, APIs, and web applications.
We welcome responsible disclosure of security vulnerabilities. Contact our security team to report any issues you find.
We use security scanning tools and dependency monitoring as part of our development process to identify and remediate vulnerabilities before they reach production.
Our security team monitors for threats with automated incident response playbooks and proactive alert systems.
Found a security issue?