Security and privacy

Airparser Trust Center

Security, privacy, AI data handling, subprocessors, and legal commitments for teams evaluating Airparser.

Have security or vendor review questions?

Contact security

Trust overview

What Airparser protects and how our security program is organized.

Airparser processes documents, emails, extraction schemas, and structured outputs on behalf of customers. This hub brings the security, privacy, AI data handling, subprocessors, GDPR, and DPA pages into one navigable trust center for customer and vendor reviews.

Documented

GDPR-ready processor

DPA available, SCCs used where required, EU-based compute provider.

Contractual controls

No training on customer data

Airparser does not train or fine-tune models on customer documents.

Implemented

Encrypted by default

TLS 1.2+ in transit and AES-256 encryption at rest.

Vendor-held

Vendor certifications

Key infrastructure and service providers maintain recognized security programs.

Security controls

Current controls, organized for security review.

Access Control and Authorization

Limit internal access to the people and systems that need it.

  • Least-privilege access

    In place

    Access to customer data and production systems is limited to authorized team members with a business need.

  • Multi-factor authentication

    In place

    MFA is required for company tools used to operate and support Airparser.

  • Password manager in use

    In place

    Team credentials are managed through a company-wide password manager.

  • User passwords hashed

    In place

    Airparser account passwords are salted and hashed with bcrypt using a work factor of 12.

  • Endpoint disk encryption

    In place

    Employee laptops use full-disk encryption to protect company data on local devices.

Data Management and Protection

Protect documents, schemas, results, and exports through their lifecycle.

  • Data encrypted in transit

    In place

    Web, API, and provider communications use HTTPS with TLS 1.2 or higher.

  • Data encrypted at rest

    In place

    Documents, application data, and backups are protected with AES-256 encryption at rest.

  • Configurable retention

    In place

    Customers can set automatic document deletion from 1 to 180 days.

  • Customer deletion supported

    In place

    Customers can delete documents, schemas, and accounts; deleted data is removed from active systems.

  • Payment data isolated

    In place

    Card payments are processed by Stripe; Airparser does not store card details.

Infrastructure Security

Operate on segmented, monitored infrastructure with vetted cloud providers.

  • EU-based core compute

    In place

    Compute and networking run on Hetzner in Germany across two independent locations.

  • Private server network

    In place

    Servers communicate over a private network that is not exposed to the public internet.

  • Network segmentation

    In place

    Firewalls and network boundaries restrict access to internal services.

  • Encrypted object storage

    In place

    Customer documents and exports are stored in encrypted Amazon S3 buckets.

  • Managed application database

    In place

    Application data such as accounts and extraction schemas is stored in MongoDB Atlas.

  • Systems patched regularly

    In place

    Operating systems and dependencies are updated to reduce known vulnerability exposure.

Monitoring and Incident Response

Detect reliability or security issues and respond through documented procedures.

  • Infrastructure monitored 24/7

    In place

    Core infrastructure is monitored continuously with real-time alerting.

  • Centralized logging

    In place

    Logs are aggregated centrally to support investigation, reliability, and security operations.

  • Audit logs maintained

    In place

    Internal audit logs track authentication, access, and system actions.

  • Incident response documented

    In place

    Incident response and escalation procedures are documented for security and reliability events.

  • Regulatory notification process

    In place

    When required by law, affected parties and authorities are notified within applicable timelines.

Vulnerability Management

Reduce risk before changes reach production.

  • Peer review before release

    In place

    Code changes are reviewed before they are shipped to production.

  • Static analysis in development

    In place

    Automated checks help identify common code quality and security issues.

  • Dependency scanning

    In place

    Application dependencies are scanned for known vulnerabilities.

  • Infrastructure scanning

    In place

    Infrastructure and application surfaces are scanned to identify remediation work.

  • Automated test coverage

    In place

    Automated tests and deployment pipelines reduce release regressions.

Disaster Recovery and Availability

Keep the service resilient and recoverable when infrastructure fails.

  • Automated backups

    In place

    Backups run regularly and are stored securely.

  • Backup rotation defined

    In place

    Backups roll over on a fixed schedule of 30 days or less.

  • Redundant infrastructure locations

    In place

    Core compute is distributed across two independent German locations.

  • Documented recovery procedures

    In place

    Recovery procedures are documented for service restoration scenarios.

  • Status page available

    In place

    A public status page provides live availability and incident history.

Organizational Security

Apply internal practices that reduce human and vendor risk.

  • Security training provided

    In place

    Employees complete security and privacy training.

  • Confidentiality obligations

    In place

    Employees are bound by confidentiality obligations for customer and company data.

  • Subprocessors reviewed

    In place

    Subprocessors are reviewed for security and privacy before onboarding.

  • Subprocessor list maintained

    In place

    The public subprocessor page lists current vendors, purposes, and locations.

Privacy and Compliance

Document customer rights, processor obligations, and data transfer safeguards.

  • DPA available

    In place

    Airparser provides a Data Processing Agreement for customers using Airparser as a processor.

  • GDPR roles documented

    In place

    For parsing services, customers act as controllers and Airparser acts as processor.

  • SCCs used where needed

    In place

    Standard Contractual Clauses support applicable international data transfers.

  • Privacy policy published

    In place

    Airparser publishes privacy and cookie information for website and product users.

  • Data minimization practiced

    In place

    Airparser collects and stores the information needed to deliver and improve the service.

AI Data Handling

Use AI only for configured extraction tasks, with no model training on customer data.

  • No training on customer documents

    In place

    Airparser does not train or fine-tune models on customer documents.

  • No-training vendor commitments

    In place

    AI subprocessors are covered by contractual no-training commitments.

  • Encrypted AI provider transport

    In place

    Data sent to AI providers is encrypted in transit.

  • Customer data logically isolated

    In place

    Customer accounts, schemas, documents, and extraction results are logically separated.

  • AI subprocessors disclosed

    In place

    AI vendors used in the extraction pipeline are listed on the subprocessor page.

Public resources

Security and privacy information available today.

Legal

Data Processing Agreement

Standard DPA for customers using Airparser as a data processor.

Public
Vendor review

Subprocessor List

Current third-party vendors, purposes, company locations, and vendor resources.

Public
Security

Security Overview

Technical and organizational controls currently described in this trust center.

Public
AI security

AI Data Handling

How Airparser processes customer data across OCR, extraction models, and AI subprocessors.

Public
Vendor review

Security Questions

For customer security reviews or specific controls not covered publicly, contact our team.

Contact us

Build vs. trust platform

Third-party trust-center platform: decision point

Maintain this public trust center now, then consider a third-party trust platform when enterprise sales regularly require gated evidence, automated questionnaire workflows, control evidence, or audit readiness tracking.

Build ourselves now

  • Fastest path to a credible public trust center.
  • No risk of displaying certifications Airparser does not hold.
  • Keeps public content tightly aligned with the existing site and SEO pages.
  • Good fit while the public hub is the primary source of security and privacy information.

Adopt a platform later

  • Useful when formal audits, assessments, or control evidence become recurring sales requirements.
  • Better for NDA-gated document access, buyer approvals, and audit evidence workflows.
  • Reduces manual questionnaire work once larger prospects repeatedly ask for the same evidence.

All trust pages

Quick navigation for security reviews.