Security

Security you can verify, not just trust.

cloudsquid is ISO 27001:2022 certified and GDPR ready. Documents stay encrypted, never train AI models, and can stay in your region. Every claim on this page is documented in the Trust Center.

ISO 27001:2022
GDPR

Compliance

Certified and continuously monitored.

ISO 27001:2022

Certified Information Security Management System (ISMS). Annual independent audits keep the certification current.

GDPR

Full compliance with the EU General Data Protection Regulation. A Data Processing Agreement (DPA) is available for every enterprise customer.

Your data

Your documents stay yours.

No model training

Your documents and data are never used to train AI models. What you process stays confidential.

Zero retention mode

Documents are processed and immediately deleted after extraction, leaving complete audit trails without stored content. Available on Enterprise plans.

End-to-end encryption

TLS 1.3 in transit and AES-256 at rest, with automated key rotation protecting your data at every stage.

Data residency options

Host data in the EU, US, or other regions to meet local compliance requirements. No cross-border transfers without your explicit consent.

Infrastructure

Built on hardened infrastructure.

Enterprise cloud infrastructure

99.9% uptime SLA, multi-region redundancy, and automatic failover.

Multi-layered network security

WAF protection, intrusion detection and prevention (IDS/IPS), and complete network isolation between customer environments.

Granular access controls

Role-based access control (RBAC), multi-factor authentication (MFA), and SSO with your enterprise IdP (SAML/OAuth).

Operations

Monitored around the clock.

24/7 security operations

Continuous SOC monitoring, real-time threat detection, automated incident response, and regular penetration tests by third-party security firms.

Incident response plan

Documented procedures with 15-minute acknowledgment time, regular response exercises, and transparent customer communication.

Documentation

Every claim, documented.

Compliance certificates, security policies, and technical measures are available for review in the Trust Center:

  • Security whitepaper
  • Subprocessor list
  • Data Processing Agreement (DPA)
  • Technical and organizational measures
  • Compliance certificates
  • Penetration test summaries