Skip to content
Trust & Safety

Security at Inkscribe AI

How we protect your documents, your data, and your account.

Encryption

At rest

AES-256. All documents, extracted text, and ScribIQ conversations are encrypted at rest in our database and object storage.

In transit

TLS 1.3 enforced for all connections. TLS 1.2 accepted for legacy integration compatibility. No unencrypted HTTP traffic.

API keys

API keys are hashed with bcrypt before storage. Not even Inkscribe AI staff can read your API key after issuance — rotate from Settings if lost.

Access Controls

User isolation

Every document, ScribIQ session, and extraction result is scoped to the authenticated user. Row-level security is enforced at the database layer — no shared-table leakage is possible.

Staff access

Inkscribe AI staff cannot view your documents or ScribIQ conversations in the course of normal operations. Support access requires your explicit written request and is logged.

Two-factor authentication

TOTP-based 2FA is available on all accounts. We recommend enabling it from Settings → Security.

Infrastructure

Hosting

Inkscribe AI is hosted on Vercel (edge) and Supabase (database and storage) — both SOC 2 Type II certified providers.

Data region

Primary data region: North America (US East). EU data residency available on Enterprise plans.

Backups

Database is backed up daily with 30-day retention. Point-in-time recovery available.

Uptime

We target 99.9% uptime. Historical uptime and ongoing incidents are tracked on the Status page.

Data Practices

Training data

Your documents, text extractions, and ScribIQ conversations are never used to train or fine-tune any AI model. We do not sell or share your data with third parties.

Data retention

Documents are retained for the lifetime of your account. Deleted documents are purged from our servers within 24 hours. On account closure, all data is deleted within 30 days.

Third parties

Document files are sent to our OCR processing pipeline. ScribIQ queries are processed via our AI provider. Both operate under data processing agreements that prohibit training use.

Compliance

GDPR

Inkscribe AI is GDPR compliant. EU and UK users have the right to access, correct, and delete their personal data. Data Processing Agreements available on request.

CCPA

California residents have the right to know what personal data we hold and to request deletion. Contact privacy@inkscribe.ai.

SOC 2

Our infrastructure providers (Vercel, Supabase) are SOC 2 Type II certified. A full platform SOC 2 audit is planned for 2027.

Vulnerability Disclosure

Report a vulnerability

If you discover a security vulnerability in Inkscribe AI, please email security@inkscribe.ai. We request coordinated disclosure and aim to triage all reports within 48 hours.

Bug bounty

We do not currently operate a formal bug bounty programme, but we will acknowledge and reward significant vulnerability disclosures at our discretion.

PGP key

A PGP public key for security@inkscribe.ai is available on request for encrypted disclosure submissions.

Have a security concern?

Email us at security@inkscribe.ai — we triage all reports within 48 hours.

Read Privacy Policy →