Everything about the way Docurensic handles sensitive files assumes they matter. You decide what's kept and where it lives — and it's encrypted, at rest and in transit, either way.
Every upload uses temporary processing that is deleted after analysis. Pick the retention posture that fits your policy per account, and change it whenever you like.
Full report retained; the original is encrypted in File Vault when storage and quota are available.
No new source copy is created; an existing vault or connected-storage source remains under your control.
Encrypted per account with AES-256-GCM — yours until you delete.
Documents you keep are encrypted at rest with AES-256-GCM and a key derived per account — encryption happens before bytes reach storage, and every request travels over TLS.
Your documents are never used to train AI models — ours or anyone else's. The reasoning layer works from extracted findings, and prompts aren't stored by default.
Reads and writes are scoped to your account, and ciphertext is cryptographically bound to your account — a blob can never decrypt for another user.
Every scan is saved as a timestamped, exportable report, and your Usage dashboard tracks scan and API activity over time — so you can always show what was analyzed and when.
Outbound requests are protected against server-side request forgery, and every webhook can be verified with an HMAC signature — the platform can't be tricked into reaching where it shouldn't.
Export or delete what you keep, whenever you want. Delete a report or a vault file and it's gone — independently, in both directions.
Start in Storageless, or retain the source encrypted when File Vault is available — your call.