PaperlessZen for your IT department
At some point advancement, counsel, or the records office will bring you a document system they want, and you will be the one asked whether it is safe to say yes. This page is written for that moment. It covers where the data lives, what touches your network, what runs on staff machines, and what we ask of your environment, in plain terms, so the review starts from facts rather than a sales call.
It runs in your cloud, not ours
PaperlessZen™ deploys into your institution’s own cloud subscription. Azure is our preferred and most practiced target, and we can work with your team on AWS, Google Cloud, or another provider. That one architectural fact settles most of a security review’s opening questions:
- Residency: your documents sit in your tenancy, in the region you chose, under the provider agreements you already negotiated.
- Access: your cloud, your subscription, your keys to revoke.
- Billing: hosting stays on your existing cloud bill rather than becoming a line item you cannot inspect.
- Exit: your documents are ordinary files in your own environment. If PaperlessZen went away tomorrow, your archive would still be sitting in your subscription, originals intact.
That last point deserves to be said as plainly as we can say it. We are an early-stage vendor, and you are right to weigh vendor risk. The deployment model is our answer: the institution’s memory lives in the institution’s environment, so the worst case is losing a tool, never losing the archive.
Nothing to rip out
PaperlessZen is a document layer, not a new system of engagement. It sits under the CRM and the other systems you already run, attaches documents to the records your staff already open, and connects outward through plain-language automations. Your CRM stays the CRM. Your identity model stays your identity model. The ask is an integration review, not a replacement project.
Access, audit, and sharing
- Role-based access controls who can see, file, and govern documents, and the sensitive governance actions, retention changes and legal holds, sit behind a separate permission an ordinary account does not carry.
- A complete audit trail records every view, share, and download, exportable when someone asks to see it.
- External sharing is a single-use token that resolves to a short-lived download link, expiring on its own and revocable at any moment. No standing access, no attachment living forever in an inbox.
- Deletion is soft and overridden by retention schedules and legal holds, so a misclick cannot destroy a record.
- Single sign-on is on the near-term roadmap, and we will be straight with you about where it stands for your timeline.
The fuller treatment, including what counsel and the records office care about, is on the security page and in the trust center.
What will run on staff machines
A desktop capture app, PaperlessZen Desktop, is in development. It is the piece most likely to reach you as a shadow-IT discovery, a staff member using a tool you have not reviewed, so we would rather you know its design commitments now, before it ships:
Desktop app design commitments
Pages are processed on the machine. In single-user mode nothing is uploaded anywhere, ever.
No account and no telemetry in single-user mode. There is nothing calling home about how staff work.
Installs per user, without administrator rights, so it does not require elevation on a managed machine.
Files stay in the user's own folders. The app never destroys or alters a source file, and its index is a rebuildable cache, not a document store.
Connecting to a PaperlessZen workspace is an explicit, visible act. After connection the app uploads captured documents to your institution's workspace and nothing else.
If someone in advancement asks to pilot it when builds open, this page is meant to make sanctioning that pilot cheap: the architecture is the control, and the single-user edition, Desktop Lite, is free forever, so there is no purchase order attached to saying yes.
Straight talk about beta
PaperlessZen is an early-beta product. Everything described as enforced on this page is enforced today; everything described as designed or on the roadmap is labeled that way, including SSO, formal certifications like SOC 2, and the desktop app itself. If you have a security questionnaire, send it, and we will answer it plainly, including the questions where the honest answer is not yet. We would rather lose a review on the truth than pass one on an implication.
Talk to us before the request lands on your desk
Book a demo and bring your own questions, or send the questionnaire first and let us answer in writing. If advancement is already talking to us, ask them for the pilot plan: it is one box of documents, in your environment, under your controls.
Frequently asked questions
Where does the data live?
In your institution's own cloud subscription, Azure preferred, and we can work with your team on AWS or Google Cloud. Your documents never leave your environment, hosting stays on your existing cloud bill, and residency questions are answered by your own provider agreements.
Is our data used to train anything?
No. Your documents are read so they become searchable and classified for you. They are not used to train models for anyone else, and they are not shared across customers.
Do you support single sign-on?
Single sign-on is on the near-term roadmap. Today access is account-based with role-based permissions, and every view, share, and download is logged. We will tell you plainly where SSO stands for your timeline rather than imply it ships today.
Do you hold SOC 2 or similar certifications?
Not yet, and we will not imply otherwise. PaperlessZen is in early beta. The controls described on this page are enforced today, formal certifications are on the roadmap, and during beta every deployment runs inside the customer's own cloud subscription, which answers many of the questions a certification normally covers.
What will the desktop app do on our machines?
The desktop capture app, now in development, is designed to install per user without administrator rights, process pages entirely on the machine, and run with no account and no telemetry in single-user mode. Connecting it to a workspace is explicit, and even then it uploads captured documents and nothing else.