- Multi-tenant data isolation — every query scoped to the requesting organization
- Role-based access control (owner, admin, member, reviewer)
- Two-factor authentication (TOTP) with backup codes
- Session management with IP and user-agent tracking
- Encryption in transit (TLS 1.2+)
- Email verification on every account
- Cloudflare Turnstile CAPTCHA on auth flows
- Immutable version history per document
- Hosted on Microsoft Azure infrastructure
- Contractual commitment from AI subprocessors not to train on customer data
Our compliance status — the honest version
PaperAI is an early-stage product. This page is the single source of truth for which compliance certifications we hold (none yet), which we are working toward, and what you should not use the product for today. If anything on this site implies otherwise, tell us and we will fix it.
PaperAI does not currently hold any formal compliance certifications.
No SOC 2, no HIPAA BAA, no ISO 27001, no PCI-DSS, no FedRAMP, no HITRUST. If your workflow requires any of those to handle the documents you process, choose a vendor that holds the relevant certification today.
Certification status
| Framework | Status | Notes |
|---|---|---|
| SOC 2 Type I | Not held | Long-term goal — not yet started |
| SOC 2 Type II | Not held | Long-term goal — not yet started |
| HIPAA Business Associate Agreement (BAA) | Not available | Do not upload PHI |
| ISO 27001 | Not held | Not on near-term roadmap |
| PCI-DSS | Not held | Do not upload PCI / cardholder data |
| GDPR formal attestation | Not held | Privacy policy describes data handling |
| HITRUST | Not held | Not on near-term roadmap |
| FedRAMP | Not held | Not on near-term roadmap |
| CCPA opt-out | Honored | See Privacy Policy for the request flow |
- Process Protected Health Information (PHI). Do not upload patient names, MRNs, DOBs, or any of the 18 HIPAA identifiers.
- Process Payment Card Industry (PCI) data — cardholder numbers, CVV, magnetic stripe data.
- Sign Business Associate Agreements.
- Provide SOC 2, ISO 27001, HITRUST, or FedRAMP audit reports.
- Provide legal, medical, tax, accounting, or financial advice. Output requires qualified human review.
- Guarantee extraction accuracy. All output must be verified before use.
Subprocessors
Documents you upload pass through these third parties as part of normal operation. Each is bound by its own terms; PaperAI contracts with AI providers for API-only inference with no model training on customer data.
| Subprocessor | Purpose |
|---|---|
| Microsoft Azure | Infrastructure hosting, Azure OpenAI inference |
| Anthropic | AI inference (Claude models) |
| OpenAI | AI inference (GPT models) |
| AI inference (Gemini models) | |
| Mistral | AI inference |
| Cloudflare | CDN, DDoS protection, Turnstile CAPTCHA |
| Stripe | Payments processing |
Send security questionnaires, vulnerability reports, or specific compliance questions to hello@paperaiapp.com. We respond with what we currently offer and what's on the roadmap — no marketing puffery.
This page last reviewed: 2026-05-26