InspectMind AI logo InspectMind
For IT, Legal & Procurement

Security & Compliance Packet

One document covering everything your IT, legal, and procurement teams need to approve InspectMind: data architecture, subprocessors, authentication, retention, AI policy, and incident response.

Last updated: May 7, 2026. Source of truth for security policies is the Trust Center.

Print or save as PDFRequest DPA / MSATrust Center

1. At a glance

HostingAWS US-West-2 (Northern California)
Encryption (rest)AES-256 (S3 server-side)
Encryption (transit)TLS 1.3
AuthenticationFirebase Auth + MFA (TOTP), SSO available
SOC 2 Type IIIn progress
ISO 27001Not held
HIPAANot held; BAA available on request
GDPR postureDPA available on request
Data residencyUnited States (default); single-tenant available for enterprise
Backup retentionDaily 60-day, monthly 1-year, point-in-time 35-day
Public LLM training on customer dataNever. Doc-processing model improvement opt-out available.
Standard deletion SLAWithin 24 hours of request

We never claim certifications we don't hold. SOC 2 Type II is currently in progress; we'll publish the report and attestation here once issued.

2. Compliance status

SOC 2 Type II

In progress

Audit work is underway with a qualified third-party auditor. We will publish the Type II report and bridge letter as soon as available.

ISO 27001 / HIPAA / FedRAMP

Not held

We do not hold these certifications today. For HIPAA-covered workloads, a BAA can be discussed for enterprise deployments.

DPA & MSA

Available on request

Standard Data Processing Addendum and Master Services Agreement templates available. Email [email protected].

Vendor questionnaires

Supported

We routinely complete CAIQ, SIG, and custom vendor security questionnaires. Typical turnaround: 3-5 business days.

3. Data architecture & flow

Storage

Customer documents, project metadata, and findings are stored in Amazon S3 (US-West-2) with object-level access controls. Application database runs on AWS-managed Postgres in the same region. All files encrypted at rest with AES-256.

Compute

AWS ECS containers with least-privilege IAM roles. Background workers process documents and call LLM providers under Zero Data Retention agreements where available.

Network

All ingress and egress over TLS 1.3. Internal service-to-service traffic stays within the VPC. WAF and rate limiting at the edge.

Secrets

API keys and credentials managed via AWS Secrets Manager / Parameter Store. No secrets in source control or logs.

Data flow summary: Customer uploads files → encrypted in S3 → background workers process and call LLM providers → findings written to Postgres + S3 → customer downloads report. No customer documents leave US infrastructure outside the LLM-inference call (covered by Zero Data Retention agreements with OpenAI and Anthropic).

4. Subprocessor list

Third parties we engage to deliver the service. We give 30 days' notice before adding a new subprocessor that handles customer data.

SubprocessorPurposeRegionData handled
Amazon Web Services (AWS)Application hosting, object storage, computeUS-West-2 (Northern California)All customer documents, project metadata, user accounts
Google FirebaseAuthentication, identity, MFAUnited StatesUser credentials, session tokens, email addresses
OpenAILLM inference for document analysisUnited StatesDocument excerpts during inference. Zero Data Retention agreement in place; content not logged or retained.
AnthropicLLM inference for document analysisUnited StatesDocument excerpts during inference. Zero Data Retention agreement in place; content not logged or retained.
Google (Vertex AI / Gemini)LLM inference for document analysis (subset of workloads)United StatesDocument excerpts during inference. Prompts may be logged for policy compliance and legal disclosures; data may be transiently stored in Google facilities.
StripePayment processingUnited StatesBilling email, payment method (tokenized — we never see card numbers)
PostHogProduct analyticsUnited States (us.i.posthog.com)Anonymized usage events, page views, feature interactions
CrispCustomer support chat widgetEuropean Union (data center)Chat messages with our support team, email addresses
Google Tag Manager / Google AnalyticsMarketing analyticsUnited StatesAnonymized site traffic; not used for customer document data

Subscribe to subprocessor change notices: email [email protected] with subject "subprocessor notifications".

5. Authentication & access controls

  • Identity provider

    Firebase Authentication (Google) with email/password and OAuth (Google sign-in). Token-based session management with token validation on every request.

  • Multi-factor authentication

    TOTP-based MFA available (works with DUO, Google Authenticator, 1Password, Authy). Org admins can require MFA for all users in the organization.

  • Single sign-on (SSO)

    SAML 2.0 SSO available for enterprise customers. Works with Okta, Azure AD / Entra ID, Google Workspace, OneLogin. SCIM provisioning available on request.

  • Role-based access control

    Four roles: Owner (project creator), Org Admin (firmwide management), Editor (full edit + invite), Viewer (read-only). See the team-access guide for details.

  • Audit logs

    Authentication events, project access, and admin actions logged. Available to org admins on request.

6. AI & model training policy

What we never do

  • We do not use your documents to train public LLMs (ChatGPT, Claude, Gemini, etc.).
  • We do not share your documents with other customers — strict data segregation between organizations.
  • Our LLM providers are contractually prohibited from using your content for their model training.

What we may do (with opt-out)

We may use your documents to improve our document-processing models — narrow models that read drawings, extract text, and identify content regions. This use does not rely on the substantive content of your documents in a way that could identify you or your projects.

You can opt out at any time by emailing [email protected]. Enterprise contracts can specify default opt-out for the entire organization.

Third-party LLM providers

  • OpenAI: Zero Data Retention agreement. Content not logged or retained.
  • Anthropic: Zero Data Retention agreement. Content not logged or retained.
  • Google (Vertex AI): Standard enterprise terms. Prompts may be logged for policy compliance and legal disclosures; data may be transiently stored in Google facilities.

7. Backup, retention & deletion

Backups

Automated daily database backups with 60-day retention. Monthly backups with 1-year retention. Point-in-time recovery available for the last 35 days. S3 file versioning enabled.

Retention

Customer data retained for the duration of the active subscription. Enterprise customers can configure automatic deletion after 30, 60, or 90 days post-project completion.

Deletion on request

Standard SLA: full deletion within 24 hours of request to [email protected]. Includes primary storage and active backup snapshots.

Single-tenant deployment

Available for enterprise customers with strict data isolation requirements (e.g. AutoZone-style partner instance). Dedicated AWS account, isolated database, custom retention policy.

8. Incident response

  • Documented IR plan covering detection, triage, containment, eradication, recovery, and post-incident review.
  • Customer notification: we notify affected customers without undue delay in the event of a confirmed data breach. Enterprise contracts can specify a fixed notification window (typically 72 hours).
  • Status page: service disruptions reported via [email protected] email and on the customer dashboard.
  • Vulnerability disclosure: security researchers can report findings to [email protected].

9. Standard documents

Email [email protected] with the subject "security review" to request any of:

  • Master Services Agreement (MSA)
  • Data Processing Addendum (DPA)
  • Business Associate Agreement (BAA) — for HIPAA workloads
  • Completed CAIQ or SIG questionnaire
  • Insurance certificates (E&O, Cyber Liability)
  • Penetration test summary (NDA may apply)
  • SOC 2 Type II report (once issued)

Questions about this packet?

Reach out to our security team. We aim to respond within one business day.

InspectMind AI Inc. · 156 2nd St, San Francisco, CA, USA