This page is written for the people who say no: IT, security, and compliance. It describes exactly where documents go, what is stored, and what your institution controls.
Processing always runs server-side — nothing runs on the analyst's machine, and there is no Excel plugin to clear through bank IT. What changes between tiers is where that server sits.
Every extracted field stores (document, page, bounding box, raw text, confidence score, timestamp, analyst action). Overrides never overwrite — they append. This is the audit trail your compliance team reviews.
Client documents are used to serve your extractions — nothing else. No training, no cross-client pooling.
Each institution runs in an isolated workspace, encrypted in transit and at rest, with role-based access control and retention policies your admin configures.
Supervisors see usage telemetry — workload, review flags, spend — never the underlying client documents.
The managed-cloud tier runs in the São Paulo region. Where data crosses borders (e.g. model inference), it is disclosed and controllable — including fully in-country options.
PII detection and masking on uploaded documents, DPA on record, configurable retention with auto-purge, and a named contact for data-protection matters.
The admin dashboard shows, per dataset, where data lives and whether it leaves Brazil — so your compliance team audits residency instead of trusting a slide.
SOC 2 Type II preparation is on our roadmap ahead of bank-wide deployments. Security documentation — architecture, data flows, and the citation-log design — is available today for your IT team's review.
We'd rather answer the hard questions before the pilot than after.
Talk to usDownload one-page summary (PDF)