One document covering everything your IT, legal, and procurement teams need to approve InspectMind: data architecture, subprocessors, authentication, retention, AI policy, and incident response.
Last updated: May 7, 2026. Source of truth for security policies is the Trust Center.
| Hosting | AWS US-West-2 (Northern California) |
| Encryption (rest) | AES-256 (S3 server-side) |
| Encryption (transit) | TLS 1.3 |
| Authentication | Firebase Auth + MFA (TOTP), SSO available |
| SOC 2 Type II | In progress |
| ISO 27001 | Not held |
| HIPAA | Not held; BAA available on request |
| GDPR posture | DPA available on request |
| Data residency | United States (default); single-tenant available for enterprise |
| Backup retention | Daily 60-day, monthly 1-year, point-in-time 35-day |
| Public LLM training on customer data | Never. Doc-processing model improvement opt-out available. |
| Standard deletion SLA | Within 24 hours of request |
We never claim certifications we don't hold. SOC 2 Type II is currently in progress; we'll publish the report and attestation here once issued.
Audit work is underway with a qualified third-party auditor. We will publish the Type II report and bridge letter as soon as available.
We do not hold these certifications today. For HIPAA-covered workloads, a BAA can be discussed for enterprise deployments.
Standard Data Processing Addendum and Master Services Agreement templates available. Email [email protected].
We routinely complete CAIQ, SIG, and custom vendor security questionnaires. Typical turnaround: 3-5 business days.
Customer documents, project metadata, and findings are stored in Amazon S3 (US-West-2) with object-level access controls. Application database runs on AWS-managed Postgres in the same region. All files encrypted at rest with AES-256.
AWS ECS containers with least-privilege IAM roles. Background workers process documents and call LLM providers under Zero Data Retention agreements where available.
All ingress and egress over TLS 1.3. Internal service-to-service traffic stays within the VPC. WAF and rate limiting at the edge.
API keys and credentials managed via AWS Secrets Manager / Parameter Store. No secrets in source control or logs.
Third parties we engage to deliver the service. We give 30 days' notice before adding a new subprocessor that handles customer data.
| Subprocessor | Purpose | Region | Data handled |
|---|---|---|---|
| Amazon Web Services (AWS) | Application hosting, object storage, compute | US-West-2 (Northern California) | All customer documents, project metadata, user accounts |
| Google Firebase | Authentication, identity, MFA | United States | User credentials, session tokens, email addresses |
| OpenAI | LLM inference for document analysis | United States | Document excerpts during inference. Zero Data Retention agreement in place; content not logged or retained. |
| Anthropic | LLM inference for document analysis | United States | Document excerpts during inference. Zero Data Retention agreement in place; content not logged or retained. |
| Google (Vertex AI / Gemini) | LLM inference for document analysis (subset of workloads) | United States | Document excerpts during inference. Prompts may be logged for policy compliance and legal disclosures; data may be transiently stored in Google facilities. |
| Stripe | Payment processing | United States | Billing email, payment method (tokenized — we never see card numbers) |
| PostHog | Product analytics | United States (us.i.posthog.com) | Anonymized usage events, page views, feature interactions |
| Crisp | Customer support chat widget | European Union (data center) | Chat messages with our support team, email addresses |
| Google Tag Manager / Google Analytics | Marketing analytics | United States | Anonymized site traffic; not used for customer document data |
Subscribe to subprocessor change notices: email [email protected] with subject "subprocessor notifications".
Firebase Authentication (Google) with email/password and OAuth (Google sign-in). Token-based session management with token validation on every request.
TOTP-based MFA available (works with DUO, Google Authenticator, 1Password, Authy). Org admins can require MFA for all users in the organization.
SAML 2.0 SSO available for enterprise customers. Works with Okta, Azure AD / Entra ID, Google Workspace, OneLogin. SCIM provisioning available on request.
Four roles: Owner (project creator), Org Admin (firmwide management), Editor (full edit + invite), Viewer (read-only). See the team-access guide for details.
Authentication events, project access, and admin actions logged. Available to org admins on request.
We may use your documents to improve our document-processing models — narrow models that read drawings, extract text, and identify content regions. This use does not rely on the substantive content of your documents in a way that could identify you or your projects.
You can opt out at any time by emailing [email protected]. Enterprise contracts can specify default opt-out for the entire organization.
Automated daily database backups with 60-day retention. Monthly backups with 1-year retention. Point-in-time recovery available for the last 35 days. S3 file versioning enabled.
Customer data retained for the duration of the active subscription. Enterprise customers can configure automatic deletion after 30, 60, or 90 days post-project completion.
Standard SLA: full deletion within 24 hours of request to [email protected]. Includes primary storage and active backup snapshots.
Available for enterprise customers with strict data isolation requirements (e.g. AutoZone-style partner instance). Dedicated AWS account, isolated database, custom retention policy.
Email [email protected] with the subject "security review" to request any of:
Reach out to our security team. We aim to respond within one business day.
InspectMind AI Inc. · 156 2nd St, San Francisco, CA, USA