SECURITY — SPEC SHEET
Security and compliance for document AI
Sygnet processes contracts, claims and identity documents — the most sensitive files a company holds. Security is not a feature tier: every account gets the same architecture. Here is exactly how your documents are protected.
Encryption and storage
All traffic is encrypted in transit with TLS 1.2+. Documents and extracted data are encrypted at rest with AES-256. There is no plaintext storage at any stage of the pipeline.
All processing and storage runs on infrastructure located in the European Union (Google Cloud, europe-west1). Your documents never leave the EU.
Your documents never train models
Documents processed by Sygnet are used to produce your extractions — nothing else. They are never used to train or fine-tune models, neither by us nor by our model providers, with whom we contract zero-retention terms.
Role-based access and audit trails
Access to documents and extraction results is scoped by role. Every extraction, review, edit and export is recorded in an audit log, so you can always answer who saw what, and when.
- Role-based access control (RBAC) on every workspace
- Complete audit log of extractions and reviews
- Document retention windows under your control
- OAuth 2.0 single sign-on (Google, Microsoft)
GDPR today, SOC 2 underway
Sygnet is operated from France and built GDPR-compliant by design: EU data residency, data minimization, deletion on request, and a documented subprocessor list available to customers.
A SOC 2 compliance program is underway. If your procurement process requires specific documentation — DPA, security questionnaire, subprocessor list — we provide it during the pilot.
NEXT STEP