Security & Compliance
Your documents are sensitive. iCaptur.AI is built from the ground up with enterprise security, compliance certifications, and zero-retention guarantees.
Compliance Certifications
iCaptur.AI is fully GDPR compliant. We act as a data processor under your instructions, with a DPA available on request.
HIPAA compliance is available on Professional and Enterprise plans. We sign a BAA and support healthcare data with zero retention.
Our SOC 2 Type II report is available to enterprise customers under NDA. Annual third-party audits.
Actively pursuing ISO 27001 certification. ISMS fully implemented, certification audit expected Q3 2026.
Security Architecture
AES-256 Encryption
All documents and extracted data encrypted at rest using AES-256 and in transit using TLS 1.3. Per-tenant keys managed in HSM.
Zero Data Retention (API)
Documents submitted to extraction APIs are processed in memory and immediately discarded after extraction.
Role-Based Access Control
Fine-grained RBAC at organization, team, project, and document level. Supports SSO via Okta, Azure AD, Google Workspace.
Full Audit Logs
Every API call, document access, user action, and configuration change is logged immutably.
Data Residency
Enterprise customers choose data processing and storage region: US, EU, or APAC. No cross-region data movement.
Penetration Testing
Annual penetration testing by independent third party. Summary reports available to Enterprise customers under NDA.
Vulnerability Disclosure
Responsible disclosure program. Security reports acknowledged within 24 hours at security@icaptur.ai.
Backup & Recovery
iRepo data backed up every 6 hours with point-in-time recovery. RTO <4 hours, RPO <6 hours.