SECURITY — SPEC SHEET

Security and compliance for document AI

Sygnet processes contracts, claims and identity documents — the most sensitive files a company holds. Security is not a feature tier: every account gets the same architecture. Here is exactly how your documents are protected.

FIG. 01DATA PROTECTION

Encryption and storage

All traffic is encrypted in transit with TLS 1.2+. Documents and extracted data are encrypted at rest with AES-256. There is no plaintext storage at any stage of the pipeline.

All processing and storage runs on infrastructure located in the European Union (Google Cloud, europe-west1). Your documents never leave the EU.

FIG. 02MODEL POLICY

Your documents never train models

Documents processed by Sygnet are used to produce your extractions — nothing else. They are never used to train or fine-tune models, neither by us nor by our model providers, with whom we contract zero-retention terms.

FIG. 03ACCESS CONTROL

Role-based access and audit trails

Access to documents and extraction results is scoped by role. Every extraction, review, edit and export is recorded in an audit log, so you can always answer who saw what, and when.

  • Role-based access control (RBAC) on every workspace
  • Complete audit log of extractions and reviews
  • Document retention windows under your control
  • OAuth 2.0 single sign-on (Google, Microsoft)
FIG. 04COMPLIANCE

GDPR today, SOC 2 underway

Sygnet is operated from France and built GDPR-compliant by design: EU data residency, data minimization, deletion on request, and a documented subprocessor list available to customers.

A SOC 2 compliance program is underway. If your procurement process requires specific documentation — DPA, security questionnaire, subprocessor list — we provide it during the pilot.

NEXT STEP

See it on your own documents.