Security at Inkscribe AI
How we protect your documents, your data, and your account.
Encryption
At rest
AES-256. All documents, extracted text, and ScribIQ conversations are encrypted at rest in our database and object storage.
In transit
TLS 1.3 enforced for all connections. TLS 1.2 accepted for legacy integration compatibility. No unencrypted HTTP traffic.
API keys
API keys are hashed with bcrypt before storage. Not even Inkscribe AI staff can read your API key after issuance — rotate from Settings if lost.
Access Controls
User isolation
Every document, ScribIQ session, and extraction result is scoped to the authenticated user. Row-level security is enforced at the database layer — no shared-table leakage is possible.
Staff access
Inkscribe AI staff cannot view your documents or ScribIQ conversations in the course of normal operations. Support access requires your explicit written request and is logged.
Two-factor authentication
TOTP-based 2FA is available on all accounts. We recommend enabling it from Settings → Security.
Infrastructure
Hosting
Inkscribe AI is hosted on Vercel (edge) and Supabase (database and storage) — both SOC 2 Type II certified providers.
Data region
Primary data region: North America (US East). EU data residency available on Enterprise plans.
Backups
Database is backed up daily with 30-day retention. Point-in-time recovery available.
Uptime
We target 99.9% uptime. Historical uptime and ongoing incidents are tracked on the Status page.
Data Practices
Training data
Your documents, text extractions, and ScribIQ conversations are never used to train or fine-tune any AI model. We do not sell or share your data with third parties.
Data retention
Documents are retained for the lifetime of your account. Deleted documents are purged from our servers within 24 hours. On account closure, all data is deleted within 30 days.
Third parties
Document files are sent to our OCR processing pipeline. ScribIQ queries are processed via our AI provider. Both operate under data processing agreements that prohibit training use.
Compliance
GDPR
Inkscribe AI is GDPR compliant. EU and UK users have the right to access, correct, and delete their personal data. Data Processing Agreements available on request.
CCPA
California residents have the right to know what personal data we hold and to request deletion. Contact privacy@inkscribe.ai.
SOC 2
Our infrastructure providers (Vercel, Supabase) are SOC 2 Type II certified. A full platform SOC 2 audit is planned for 2027.
Vulnerability Disclosure
Report a vulnerability
If you discover a security vulnerability in Inkscribe AI, please email security@inkscribe.ai. We request coordinated disclosure and aim to triage all reports within 48 hours.
Bug bounty
We do not currently operate a formal bug bounty programme, but we will acknowledge and reward significant vulnerability disclosures at our discretion.
PGP key
A PGP public key for security@inkscribe.ai is available on request for encrypted disclosure submissions.
Have a security concern?
Email us at security@inkscribe.ai — we triage all reports within 48 hours.