Trust centre

Your paperwork is often your most sensitive data.

Here is exactly how Formalini handles it — in plain language, with no security theatre.

Private storage

Files sit in private storage. Links are short-lived and signed — there is no public URL for your documents.

Access control

Every record is bound to a workspace. Personal vaults are separate spaces no team can read.

AI processing

Documents are sent to our AI provider only to extract the fields you asked for, and are not used to train models.

Traceability

Original file, extracted values, corrections and approvals are kept together with timestamps.

Deletion

Delete a file or your account and the stored original and extracted values go with it.

Hosting

Application and database run on managed European-capable cloud infrastructure with encryption in transit and at rest.

How it works in detail

Where your data sits

Documents and extracted data are held in managed European infrastructure. Each workspace records its storage region, shown in workspace settings.

Backups

The database is backed up daily by the managed platform with point-in-time recovery. Backups inherit the same access restrictions as live data.

Keeping periods

Each workspace sets how long documents are kept. A nightly clean-up removes anything past that period, unless legal hold is switched on.

Incident response

We investigate reports the same working day, contain first, then notify affected workspace owners by email with what happened and what we changed.

Access logging

Every workspace keeps an unchangeable activity record: sign-ins, role changes, document reads, deliveries, key creation and deletions.

Encryption

Traffic uses TLS 1.2 or newer. Files and database contents are encrypted at rest by the hosting platform (AES-256). API keys and webhook secrets are stored hashed, never in readable form.

Separation between accounts

Every record belongs to one space and is filtered by database-level rules on every read and write. Access only exists through an accepted invitation.

Who else is involved

Hosting and database, AI extraction, email delivery and payments each run through named providers, listed on the subprocessors page with what they receive.

Reporting a security issue

Email security@formalini.com with steps to reproduce. We acknowledge reports within two business days and will not pursue researchers acting in good faith.

Security contact

Write to security@formalini.com for security questions, data requests or anything that looks wrong.

Reporting a vulnerability

Send what you found and how to reproduce it to security@formalini.com. Please do not test against other people's data, do not run denial-of-service attempts, and give us 90 days before publishing. We answer within five working days and will credit you if you want.

Certifications

Formalini is an early-stage product and does not yet hold an ISO 27001 or SOC 2 certificate. We describe our actual controls above rather than implying audits we have not completed.