Security

Your clients' paperwork is the most sensitive thing they own.

So this page states what is true before it states anything persuasive, and every line can be checked against the contract or the controls below.

EU GDPR compliant
GDPRCompliant
ISO 27001, in progress
ISO 27001In progress
SOC 2 Type II, in progress
SOC 2 Type IIIn progress
Your documents
Never training dataContractually prohibited from training, for every provider we use. There is no setting to switch off, because there is no version where it is on.
Processed in
The EURead, reconciled and written to a workbook on dedicated EU infrastructure. Storage carries an EU placement, which we describe exactly in chapter II.
The contract
Published in fullThe Data Processing Agreement, with every sub-processor named. No form, no email, no sales call.
Breach notice
Within 72 hoursAnd what that message will contain is written down here, before there is anything to tell.
Delete everything
Whenever you wantClose the account and the data goes with it. Any single job can go earlier.
I

It answers the question you actually came with.

“If I upload my clients’ invoices, does that end up training somebody’s AI?”

No. Not ours, not anyone else’s.

Your documents are encrypted, private to your account, and never used to train any model. Where AI reads a document it runs through vetted providers under contract, and those contracts prohibit training on your content. There is no setting to find and switch off, because there is no version of Pileform where it is on.

II

Processed in the EU. And honest about the one part that is a placement rather than a guarantee.

  1. Read and reconciled in the EUThe pipeline that opens your documents, works out the VAT and writes the workbook runs on dedicated EU infrastructure. The provider that reads the text is in the EU too.
  2. Stored with an EU placementObject storage carries a Western-Europe location hint. That is a best-effort placement, not a contractual jurisdiction guarantee, and we would rather you heard that from us than found it in the contract.
  3. Never sent out for anything elseNo client document goes outside that path. Not for support, not for analytics, not for training.

Billing details reach a payment processor, an address reaches the email service, an error trace reaches monitoring. Each is named in the Data Processing Agreement with its own transfer mechanism, and none of them ever receives a client document. Chapter III is the complete list.

Where a claim rests on a best-effort placement rather than a contractual guarantee, we say so. A page that only prints the flattering half is not worth checking.

III

Everything that leaves, and what it carries.

Not a promise that nothing leaves. A list of exactly what does, who receives it, and what they may do with it.

Inside Pileform

Your clients’ documentsEncrypted at rest. Scoped to your account. Deleted when you say so.

Never crosses the line

Crosses the line

Document reading and categorisationReceives: the document you uploadedNever retained, never used for training
PaymentsReceives: your billing name, address and card detailsNever a client document
Transactional emailReceives: a recipient address and a linkNever a document, never its contents
Error monitoringReceives: a route, an error stage, an account emailDocument payloads are excluded
IV

The controls, in full.

Nothing here is a summary of something longer. This is the whole list.

Encryption

In transit
TLS 1.3 only. TLS 1.0, 1.1 and SSLv3 are disabled at the edge, along with weak cipher suites.
At rest
AES-256 on every stored file, receipts and generated workbooks alike, and on database rows. Keys are managed by our infrastructure providers and rotated on their schedules.
Backups
Encrypted to the same standard as primary storage.

Authentication

Passwords
Hashed with salted PBKDF2, 210,000 iterations, SHA-256. We never see or store the password itself. Minimum 12 characters, with common-password rejection.
Sessions
HTTP-only, Secure, SameSite=Lax cookies signed with HMAC. They expire on inactivity. There is no permanent “remember me”.
Sign-in
Rate limited per address and per account, with progressive lockout on repeated failures.
Email
Verification required before login. Changing the address triggers a fresh one.
OAuth
Google sign-in is supported. We never request more than the email, name and profile-picture scopes.

Isolation

Every row
Carries a foreign key to the account that owns it.
Every query
Filters by that account at the SQL level, not only in the application, so a forgotten access check still would not cross accounts.
Every object
Stored under a per-account key prefix, as capture-results/{account-id}/{job-id}.zip.
Every request
Its path is validated against the session that made it before a file is signed for download.

Network

Edge
An enterprise edge sits in front of all production traffic, with rules blocking known attack patterns.
Volume
An anycast network absorbs volumetric attacks before they reach the origin.
Origin
Dedicated EU infrastructure on private networking. Only a signed internal callback can reach the job-completion endpoint.
DNS
DNSSEC enabled.

Logging

Audit log
Sign-ins, password changes, email changes, account deletions and capture jobs are recorded with timestamp, IP and user agent.
Errors
Server-side errors are captured. Document payloads are scrubbed before transmission.
Retention
90 days for sign-in fingerprints. Job records follow the retention you configured.

Retention

Default
Seven years, beyond the six-year minimum Cyprus requires.
Configurable
Six to thirty years, by country preset, in Settings → Data & exports.
Early deletion
Any single job, on request.
Leaving
You already hold every workbook. There is nothing to extract.
V

What you can do without asking us.

Rotate your passwordFrom your account page, at any time.
Revoke a sessionSigning out remotely kills it. Changing your password invalidates the others automatically.
Delete your account, and the data with itClosing the account deletes what we hold for it. Any single capture job can go earlier, on its own.
Export everythingA portability endpoint returns everything we hold about your account, as JSON. No fee, no questions.
VI

If we get it wrong.

We will tell you within 72 hours of detecting or being notified of a breach affecting your data, as Article 33 requires. Here is what that message will contain, written down now, while there is nothing to tell.

  1. What happened, and the root cause as far as we know it.
  2. What data was affected. The specific scope, not a vague generality.
  3. What we have already done to contain and fix it.
  4. What you should do now, concretely, including whether to tell your client.

We report to the Cyprus Data Protection Commissioner where required, and publish a post-mortem where the breach is material.

VII

How to check any of this.

Read the contractThe Data Processing Agreement is published in full, with every sub-processor named, its role, its location and its transfer mechanism. No form, no sales call.Data Processing Agreement Privacy policy
Found something wrong?Good-faith security research does not result in legal action from us. Do not access another account’s data, and give us reasonable time to fix it before disclosing. We respond within two business days.security@pileform.com
Sub-processor changesActive customers are notified 30 days before any change takes effect, as Article 28 requires. Nothing is added quietly.
CertificationsGDPR: compliant, with the Data Processing Agreement published in full. SOC 2 Type II and ISO 27001: both are under way. Neither certificate has been issued yet, and the marks above say so rather than implying otherwise.

Last updated: 1 September 2026

Start with one period.

One company’s documents, exactly as they arrived. An account comes with 30 non-expiring signup pages, no card required.

Create free account