Home / Security
Security & privacy

Your documents stay yours.

Everything about the way Docurensic handles sensitive files assumes they matter. You decide what's kept and where it lives — and it's encrypted, at rest and in transit, either way.

§01 / STORAGE
You're in control

Choose whether a scan creates an encrypted source copy.

Every upload uses temporary processing that is deleted after analysis. Pick the retention posture that fits your policy per account, and change it whenever you like.

  • Store & review — keep full reports and automatically archive the analyzed original, encrypted, when File Vault storage is available and quota allows.
  • Storageless — create no new source copy; an existing vault or connected-storage file remains there, while a slim history record keeps filename/basic scan metadata, verdict, findings, safe document type, and verification hash.
  • Your File Vault — retained originals are encrypted per account and remain until you delete them.
  • Bring your own — connect Dropbox or Google Drive and files never leave your storage.

Store & review

Full report retained; the original is encrypted in File Vault when storage and quota are available.

Storageless

No new source copy is created; an existing vault or connected-storage source remains under your control.

File Vault

Encrypted per account with AES-256-GCM — yours until you delete.

§02 / SAFEGUARDS
How your data is protected

Encrypted, private, and accountable.

Encrypted in transit and at rest

Documents you keep are encrypted at rest with AES-256-GCM and a key derived per account — encryption happens before bytes reach storage, and every request travels over TLS.

Never used to train models

Your documents are never used to train AI models — ours or anyone else's. The reasoning layer works from extracted findings, and prompts aren't stored by default.

Scoped to you

Reads and writes are scoped to your account, and ciphertext is cryptographically bound to your account — a blob can never decrypt for another user.

A record you can revisit

Every scan is saved as a timestamped, exportable report, and your Usage dashboard tracks scan and API activity over time — so you can always show what was analyzed and when.

Guarded by design

Outbound requests are protected against server-side request forgery, and every webhook can be verified with an HMAC signature — the platform can't be tricked into reaching where it shouldn't.

No lock-in on your data

Export or delete what you keep, whenever you want. Delete a report or a vault file and it's gone — independently, in both directions.

Try it with your own storage posture.

Start in Storageless, or retain the source encrypted when File Vault is available — your call.