Security and privacy

Parsio Trust Center

Security, privacy, AI data handling, subprocessors, and legal commitments for teams evaluating Parsio.

Have security or vendor review questions?

Contact security

Trust overview

How Parsio protects documents, emails, templates, prompts, and extracted data.

Parsio combines rule-based parsing, AI extraction, OCR, and integrations. This hub brings the current security, privacy, AI data handling, subprocessors, GDPR, and DPA information into one place for customer and vendor reviews.

No training Customer data never trains AI models
Germany EU-based core compute
DPA DPA available
1-180 days Configurable retention

Security controls

Current controls, grouped for security review.

Access & authentication

Grouped by category, drawn from the detailed sections below.

  • Bcrypt password hashing (work factor 12)

    In place
  • Company-wide multi-factor authentication

    In place
  • Company-wide password manager

    In place
  • Least-privilege access, audited regularly

    In place
  • Full-disk encryption on employee laptops

    In place

Data protection

Grouped by category, drawn from the detailed sections below.

  • TLS 1.2+ for all traffic

    In place
  • AES-256 encryption at rest

    In place
  • Encrypted Amazon S3 document storage

    In place
  • PCI DSS compliant payments (Stripe) — we never store card details

    In place
  • Configurable retention, 1–180 days

    In place

Infrastructure

Grouped by category, drawn from the detailed sections below.

  • Hetzner compute, ISO/IEC 27001-certified (Germany)

    In place
  • Redundant across two independent locations

    In place
  • Firewalls and network segmentation

    In place
  • Private network between servers, inaccessible from outside

    In place
  • Regular OS and dependency patching

    In place
  • Blue/green and rolling deployments for safe releases

    In place

Vulnerability management

Grouped by category, drawn from the detailed sections below.

  • Peer review before every release

    In place
  • Continuous static analysis and dependency scanning

    In place
  • Automated vulnerability scanning, infra and code

    In place
  • Automated test suites guard against regressions

    In place

Monitoring & logging

Grouped by category, drawn from the detailed sections below.

  • 24/7 infrastructure monitoring, real-time alerts

    In place
  • Centralized log aggregation

    In place
  • Auditable access and key actions across the platform

    In place

Incident response

Grouped by category, drawn from the detailed sections below.

  • Documented incident-response and escalation procedures

    In place
  • Continuous monitoring to detect unusual activity

    In place
  • 72-hour breach notification, where required by law

    In place

Disaster recovery & availability

Grouped by category, drawn from the detailed sections below.

  • Frequent, automated backups

    In place
  • Backups roll over on a fixed schedule (30 days or less)

    In place
  • Routine restore-procedure verification

    In place
  • Distributed, horizontally scalable databases

    In place

Organizational security

Grouped by category, drawn from the detailed sections below.

  • Security and privacy training for all employees

    In place
  • Confidentiality obligations for every employee

    In place
  • Subprocessors vetted for security and privacy before onboarding

    In place

Compliance

Grouped by category, drawn from the detailed sections below.

  • GDPR-compliant; DPA available to every customer

    In place
  • SCCs cover international data transfers

    In place
  • Infrastructure providers hold ISO/IEC 27001 certification

    In place

AI & data use

Grouped by category, drawn from the detailed sections below.

  • Contractual no-training clause with every AI vendor

    In place
  • Encrypted communication with AI providers

    In place
  • Your data is never sold or shared

    In place

Public resources

Security and privacy information available today.

Subprocessors

Current vendors used to deliver Parsio.

Amazon S3 Encrypted document and data storage
Hetzner Cloud compute and networking (Germany, ISO 27001-certified)
MongoDB Atlas Database infrastructure
Microsoft Cloud computing
OpenAI AI document extraction
Amazon Textract OCR services
Mistral OCR services
Stripe Payment processing (PCI DSS compliant)
Crisp Customer support chat
Subprocessors

Trust-center platform

Build now, consider a platform later

Parsio does not need a third-party trust-center platform just to publish accurate public security information. A platform becomes useful when enterprise sales repeatedly needs NDA workflows, questionnaire automation, formal audit evidence, or buyer approval tracking.

All trust pages

Quick navigation for security reviews.