security

Your rate cons, handled carefully.

We don't sell your data, we don't train models on it, and every document is encrypted end to end. Full detail below.

Encryption
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, across our infrastructure and sub-processors.
Access control
Employee access to customer data is restricted on a need-only basis and logged. No standing access to document contents.
Vulnerability management
We run regular vulnerability assessments against our infrastructure and application layer.
Sub-processor oversight
Every sub-processor — cloud infrastructure, AI extraction providers, payment processors — operates under a signed data processing agreement.
Data retention controls
Extraction history follows your plan's retention window (30 days Starter, 12 months Pro/Team). Deleted data clears from backups within 90 days.
No model training on your data
We don't use uploaded documents or extracted data to train third-party models. Model improvements use aggregate, de-identified patterns only.
Need documentation for your vendor review?

Our Data Processing Agreement covers sub-processors, breach notification, and audit rights. A current sub-processor list is available on request.

Security questions.

Do you have SOC 2 or similar certification?

Not yet — we're an early-stage company and haven't pursued formal certification. Happy to discuss your specific compliance requirements directly.

Where is data hosted?

On AWS infrastructure in the US. If you're in the EU or UK, data may be processed under Standard Contractual Clauses — see our Data Processing Agreement.

Who can access my documents?

Only employees who need access to operate or support the Service, on a need-only basis. Our third-party AI sub-processors process documents to return extraction results and don't use them to train their own models.

What happens to a document after it's processed?

It's deleted after successful extraction, or retained per your plan's history window — see our Privacy Policy for exact timelines.

How do I report a security issue?

Email security@freyt.space. We take reports seriously and will acknowledge within 2 business days.