Trust center

Before advancement can bring in a document system, three offices have to say yes: counsel, IT, and records. They ask hard questions, and they should. This page puts the answers in one place, and it holds the same honesty standard we hold everywhere: what is enforced today, stated plainly, and what is on the roadmap, labeled as such.

The three questions every review asks

Security for a document system comes down to three questions. Who can see this? Who has seen it? And if we need to, can we take access back?

What a security review is really asking
1

Who can see it

Role-based access, with governance actions behind a separate permission. Sensitive by default.

2

Who has seen it

A complete audit trail: every view, share, and download recorded and producible on demand.

3

Can we revoke it

External shares are single-use tokens resolving to short-lived links. Revoke, and the share is closed at once.

We answer all three without hedging on the security page, which walks through each control in detail. This trust center is the wider view: security, privacy, governance, and the paperwork your reviewers will want.

What’s enforced today

Everything in this list is live in the product now, not a roadmap slide.

Enforced today

Role-based access, with governance actions behind a separate permission.

Deployment into your own cloud subscription, so your documents never leave your environment.

Files served through signed links that expire after a short window.

External shares as single-use tokens you can revoke immediately.

Retention schedules and legal holds that override deletion.

Soft-delete, so an ordinary delete keeps the underlying file.

A complete audit trail of every view, share, and download.

Originals never altered: we work alongside the file, never inside it, and keep every version.

Privacy and your data

Your documents live in your institution’s own cloud subscription, on infrastructure you already govern. They are not used to train anything, not commingled with another organization’s archive, and not shared beyond the people you grant access to. When you ask the archive a question, it retrieves the passage and the page from your own documents; it does not send your documents somewhere to have an answer composed about them.

We collect the minimum needed to run the service and to contact the people you designate. For the specifics, see our privacy policy and terms and conditions. For a data processing agreement or a current list of subprocessors, ask during a demo or review and we’ll provide them.

For the offices that have to sign off

Each reviewer is asking a slightly different question. Here is where each one’s concern is answered.

What they're worried about

General counsel: are the originals safe, and can holds be enforced?

IT: does this isolate our data and integrate without a rip-out?

Records: is this a real retention and audit system, or a drive?

How this answers it

Originals never altered, every version kept, legal holds override deletion.

Runs in your own cloud subscription and sits under your stack, nothing to replace.

Retention schedules, holds, disposition, and a full audit trail, enforced.

Counsel and records will find their own page useful too: for general counsel and for records and archives.

Send us your questionnaire

If your institution has a security or vendor questionnaire, send it. We will answer every line, and where the honest answer is “planned, not shipped,” we will say so rather than checking a box we can’t back. We’d rather lose a deal on the truth than win one on a claim that falls apart in production.

We hold the same honesty standard in how we sell as in the product.

Straight talk about beta

PaperlessZen is an early-beta product. The controls on this page are enforced today. During beta, every deployment runs in the customer’s own cloud, so the hosting questions a review opens with, provider, region, encryption, residency, are answered by your own environment and your existing agreements. What remains, our software practices and our roadmap toward formal certifications like SOC 2, we are glad to cover directly with your team, and we will be honest about what is in place now versus what is on the roadmap.

Want to walk your security team through it? Book a demo and bring them, or read the detailed security page first.

Frequently asked questions

Where do our documents actually live?

In your own cloud, not ours. PaperlessZen is deployed into your institution's cloud subscription, Microsoft Azure preferred, with AWS, Google Cloud, or another provider workable with your team. Your documents never leave your environment and are never commingled with another organization's. You are the custodian. Your documents remain yours.

Do you have formal certifications like SOC 2?

PaperlessZen is in early beta. The controls on this page are enforced today. Formal certifications are on the roadmap, and we will tell you plainly what exists now versus what is planned. Send your security questionnaire and we'll answer every line honestly.

Can we get a DPA and a list of subprocessors?

Yes. Ask as part of a demo or security review and we'll provide our current data processing terms and the subprocessors we rely on. We'd rather be clear than impressive about where we are.

Who can place a legal hold or change retention?

Only accounts with a separate governance permission. Setting a retention schedule or placing a legal hold is deliberately gated so it is never something an ordinary account does by accident.

Book a demo