Features Use Cases Docs Pricing Security Log in
Security & Compliance

Your data is protected
at every layer.

Defense-in-depth security with encryption, isolation, and comprehensive monitoring. Your docs are yours — we never train AI on your data.

GDPR Compliant
AES-256 Encrypted
No AI Training
SOC 2 Type II (in progress)
256-bit
AES Encryption
1.2+
TLS Validated
30 days
Data Backups
0
Ad Trackers

Infrastructure & Data

🔐

Encryption at rest — AES-256 via AWS KMS

All your documents and data are encrypted with AES-256 using AWS Key Management Service. Keys are rotated automatically and managed separately from your data.

🔒

Encryption in transit — TLS 1.2+ enforced everywhere

All connections use TLS 1.2 or higher with perfect forward secrecy. We disable outdated protocols and weak ciphers to ensure secure communication.

💾

Daily backups — retained 30 days, tested regularly

Automated daily backups with point-in-time recovery. We regularly test restoration procedures to ensure data integrity and availability.

🏗️

Tenant isolation — every project's data logically isolated

Multi-tenant architecture with strict logical separation. Each project's data is isolated at database and application layers with no cross-tenant access.

🔑

MFA everywhere — required for all team members

Multi-factor authentication is mandatory for all OracleDoc team members accessing production systems and customer data.

Compliance & Certs

🏛️ SOC 2 Type II
In progress
🇪🇺 GDPR
Compliant
📋 DPA
Available
🔒 AES-256
Active
🌐 TLS 1.3
Active
🚫 No AI Training
Guaranteed

Data Practices

🚫

We never sell or share your data

Your documentation and conversations are yours. We don't sell, rent, or share your data with third parties for advertising or any other purpose.

🤖

Your data never trains AI models

We never use your documents, conversations, or any customer data to train AI models. Your intellectual property remains completely yours.

🗑️

Delete your account anytime

You can export and delete your data at any time. We permanently remove all your data within 30 days of account deletion.

📊

Minimal data collection

We only collect what's necessary to provide our service. No tracking pixels, no advertising cookies, no unnecessary data harvesting.

Sub-processors

Service Purpose Location
OpenAI AI/LLM
Language model inference, embeddings 🇺🇸 USA
Anthropic AI/LLM
Claude model inference 🇺🇸 USA
Google (Gemini) AI/LLM
Gemini model inference 🇺🇸 USA
Cohere Search
Semantic search reranking 🇨🇦 USA/Canada
Amazon Web Services Infra
Cloud infra, S3, SQS, RDS 🇮🇳 ap-south-1
Razorpay Payments
Payment processing and billing 🇮🇳 India
Simple Analytics Analytics
Cookieless analytics 🇳🇱 Netherlands

Global Standards

🇪🇺

GDPR

DPA with Standard Contractual Clauses available.

🇺🇸

CCPA

We do not sell your personal information.

🇮🇳

India DPDPA

Safeguards for Indian residents' data architecture.

Security question or concern?

We take all reports seriously and respond within 48 hours.

Contact Security Team → Download our DPA