Security
Your clients' paperwork is the most sensitive thing they own.
So this page states what is true before it states anything persuasive, and every line can be checked against the contract or the controls below.
- Your documents
- Never training dataContractually prohibited from training, for every provider we use. There is no setting to switch off, because there is no version where it is on.
- Processed in
- The EURead, reconciled and written to a workbook on dedicated EU infrastructure. Storage carries an EU placement, which we describe exactly in chapter II.
- The contract
- Published in fullThe Data Processing Agreement, with every sub-processor named. No form, no email, no sales call.
- Breach notice
- Within 72 hoursAnd what that message will contain is written down here, before there is anything to tell.
- Delete everything
- Whenever you wantClose the account and the data goes with it. Any single job can go earlier.
It answers the question you actually came with.
“If I upload my clients’ invoices, does that end up training somebody’s AI?”
No. Not ours, not anyone else’s.
Your documents are encrypted, private to your account, and never used to train any model. Where AI reads a document it runs through vetted providers under contract, and those contracts prohibit training on your content. There is no setting to find and switch off, because there is no version of Pileform where it is on.
Processed in the EU. And honest about the one part that is a placement rather than a guarantee.
- Read and reconciled in the EUThe pipeline that opens your documents, works out the VAT and writes the workbook runs on dedicated EU infrastructure. The provider that reads the text is in the EU too.
- Stored with an EU placementObject storage carries a Western-Europe location hint. That is a best-effort placement, not a contractual jurisdiction guarantee, and we would rather you heard that from us than found it in the contract.
- Never sent out for anything elseNo client document goes outside that path. Not for support, not for analytics, not for training.
Billing details reach a payment processor, an address reaches the email service, an error trace reaches monitoring. Each is named in the Data Processing Agreement with its own transfer mechanism, and none of them ever receives a client document. Chapter III is the complete list.
Where a claim rests on a best-effort placement rather than a contractual guarantee, we say so. A page that only prints the flattering half is not worth checking.
Everything that leaves, and what it carries.
Not a promise that nothing leaves. A list of exactly what does, who receives it, and what they may do with it.
Inside Pileform
Never crosses the line
Crosses the line
The controls, in full.
Nothing here is a summary of something longer. This is the whole list.
Encryption
- In transit
- TLS 1.3 only. TLS 1.0, 1.1 and SSLv3 are disabled at the edge, along with weak cipher suites.
- At rest
- AES-256 on every stored file, receipts and generated workbooks alike, and on database rows. Keys are managed by our infrastructure providers and rotated on their schedules.
- Backups
- Encrypted to the same standard as primary storage.
Authentication
- Passwords
- Hashed with salted PBKDF2, 210,000 iterations, SHA-256. We never see or store the password itself. Minimum 12 characters, with common-password rejection.
- Sessions
- HTTP-only, Secure, SameSite=Lax cookies signed with HMAC. They expire on inactivity. There is no permanent “remember me”.
- Sign-in
- Rate limited per address and per account, with progressive lockout on repeated failures.
- Verification required before login. Changing the address triggers a fresh one.
- OAuth
- Google sign-in is supported. We never request more than the email, name and profile-picture scopes.
Isolation
- Every row
- Carries a foreign key to the account that owns it.
- Every query
- Filters by that account at the SQL level, not only in the application, so a forgotten access check still would not cross accounts.
- Every object
- Stored under a per-account key prefix, as
capture-results/{account-id}/{job-id}.zip. - Every request
- Its path is validated against the session that made it before a file is signed for download.
Network
- Edge
- An enterprise edge sits in front of all production traffic, with rules blocking known attack patterns.
- Volume
- An anycast network absorbs volumetric attacks before they reach the origin.
- Origin
- Dedicated EU infrastructure on private networking. Only a signed internal callback can reach the job-completion endpoint.
- DNS
- DNSSEC enabled.
Logging
- Audit log
- Sign-ins, password changes, email changes, account deletions and capture jobs are recorded with timestamp, IP and user agent.
- Errors
- Server-side errors are captured. Document payloads are scrubbed before transmission.
- Retention
- 90 days for sign-in fingerprints. Job records follow the retention you configured.
Retention
- Default
- Seven years, beyond the six-year minimum Cyprus requires.
- Configurable
- Six to thirty years, by country preset, in Settings → Data & exports.
- Early deletion
- Any single job, on request.
- Leaving
- You already hold every workbook. There is nothing to extract.
What you can do without asking us.
If we get it wrong.
We will tell you within 72 hours of detecting or being notified of a breach affecting your data, as Article 33 requires. Here is what that message will contain, written down now, while there is nothing to tell.
- What happened, and the root cause as far as we know it.
- What data was affected. The specific scope, not a vague generality.
- What we have already done to contain and fix it.
- What you should do now, concretely, including whether to tell your client.
We report to the Cyprus Data Protection Commissioner where required, and publish a post-mortem where the breach is material.
How to check any of this.
Start with one period.
One company’s documents, exactly as they arrived. An account comes with 30 non-expiring signup pages, no card required.
Create free account