DocsFlow AI is a secure document intelligence platform for enterprises handling sensitive data — contracts, medical records, financial reports, and identity documents. It combines SOC 2 Type II certification, AES-256 and TLS 1.3 encryption, per-request isolated sandboxes, and a zero data retention policy that purges documents within seconds of extraction. This guide covers the certifications, controls, and audit trail the platform provides.
What security certifications does DocsFlow AI hold?
DocsFlow AI holds SOC 2 Type II certification, audited annually by an independent third party across security, availability, processing integrity, and confidentiality controls. It supports HIPAA compliance with Business Associate Agreements for healthcare customers, GDPR with data processing agreements and EU data residency, and is aligned with ISO 27001, CCPA, and PCI DSS Level 1 for billing. Audit reports and completed security questionnaires are available to enterprise customers on request.
Does DocsFlow AI store documents after processing?
No. DocsFlow AI enforces a zero data retention policy by default. Documents and intermediate files are cryptographically purged from all systems within seconds of extraction completing — no backups, no caching, and no content logs. The policy is enforced at the infrastructure level, not as a toggle, so there is no administrative override that could expose data.
How does DocsFlow AI encrypt documents?
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are unique per request, rotated on a rolling 90-day schedule, and destroyed immediately after extraction completes. DocsFlow AI never uses shared keys or shared storage at any stage of the pipeline.