Security and privacy
Parsio Trust Center
Security, privacy, AI data handling, subprocessors, and legal commitments for teams evaluating Parsio.
Have security or vendor review questions?
Contact securitySecurity at Parsio
At Parsio, the security of your data is foundational to how we design, build, and operate our platform. We combine strong technical controls with disciplined operational practices to protect confidentiality, integrity, and availability.
AES-256 at rest, TLS 1.2+ in transit
Your data never trains AI models
GDPR-compliant, DPA available
Delete data anytime, 1–180 day retention
Security controls at a glance
Grouped by category, drawn from the detailed sections below.
Access & authentication
- Bcrypt password hashing (work factor 12)
- Company-wide multi-factor authentication
- Company-wide password manager
- Least-privilege access, audited regularly
- Full-disk encryption on employee laptops
Data protection
- TLS 1.2+ for all traffic
- AES-256 encryption at rest
- Encrypted Amazon S3 document storage
- PCI DSS compliant payments (Stripe) — we never store card details
- Configurable retention, 1–180 days
Infrastructure
- Hetzner compute, ISO/IEC 27001-certified (Germany)
- Redundant across two independent locations
- Firewalls and network segmentation
- Private network between servers, inaccessible from outside
- Regular OS and dependency patching
- Blue/green and rolling deployments for safe releases
Vulnerability management
- Peer review before every release
- Continuous static analysis and dependency scanning
- Automated vulnerability scanning, infra and code
- Automated test suites guard against regressions
Monitoring & logging
- 24/7 infrastructure monitoring, real-time alerts
- Centralized log aggregation
- Auditable access and key actions across the platform
Incident response
- Documented incident-response and escalation procedures
- Continuous monitoring to detect unusual activity
- 72-hour breach notification, where required by law
Disaster recovery & availability
- Frequent, automated backups
- Backups roll over on a fixed schedule (30 days or less)
- Routine restore-procedure verification
- Distributed, horizontally scalable databases
Organizational security
- Security and privacy training for all employees
- Confidentiality obligations for every employee
- Subprocessors vetted for security and privacy before onboarding
Compliance
- GDPR-compliant; DPA available to every customer
- SCCs cover international data transfers
- Infrastructure providers hold ISO/IEC 27001 certification
AI & data use
- Contractual no-training clause with every AI vendor
- Encrypted communication with AI providers
- Your data is never sold or shared
Quick answers
Where is my data physically stored?
Parsio's compute and networking run on Hetzner, with data centers in Falkenstein and Nuremberg, Germany — both certified to ISO/IEC 27001. Documents and exports live in encrypted Amazon S3 buckets; application data (accounts, extraction templates) lives in MongoDB Atlas. Data is processed in the EU and US; where required, Standard Contractual Clauses (SCCs) cover the transfer. See our subprocessors list for the complete picture.
Is my data used to train AI models?
Never. We don't train or fine-tune any model — ours or our providers' — on your data, and we never sell it. This is a contractual commitment with every AI subprocessor we use, not a plan-dependent feature.
How are my passwords protected?
Passwords are hashed with bcrypt using a work factor of 12 — a deliberately slow, salted, one-way algorithm designed to resist brute-force and rainbow-table attacks. We never store or have access to your actual password.
What encryption do you use?
TLS 1.2+ with valid certificates for everything in transit, and AES-256 for everything at rest, including document storage and database backups.
Is Parsio GDPR-compliant?
Yes. For parsing services, you're the Data Controller and Parsio is your Data Processor. A standard Data Processing Agreement (DPA) is available to all customers, no request needed, and our core compute infrastructure is EU-based (Germany). Data is processed in the EU and US; where a subprocessor operates outside the EU, Standard Contractual Clauses (SCCs) cover the transfer. See our GDPR page and DPA.
What happens if there's a security breach?
We continuously monitor for unusual activity and follow documented incident-response procedures. If a breach occurs, affected customers and relevant authorities are notified within 72 hours where required by law.
How do you find and fix vulnerabilities?
Every code change goes through peer review before release. We run continuous static analysis, dependency scanning, and automated vulnerability scanning across our infrastructure and codebase, backed by unit/integration tests and automated pipelines that guard against regressions.
Can I delete my data?
Yes, at any time — individual documents, templates, or your entire account. Data is removed from active systems immediately. Backups roll over on their own fixed rotation schedule (not more than 30 days). You can also set automatic deletion between 1 and 180 days.
Who can access my data inside Parsio?
Access is restricted to what's strictly necessary (least privilege) and audited regularly. All employees complete security and privacy training and are bound by confidentiality obligations.
Do you sell or share my data?
No — never, under any circumstances, without your consent. Your documents, emails, and extracted data are yours.
What's your uptime?
Track live availability and incident history on our status page.
AI and data use
Parsio offers four parsing engines — AI Parser, GPT Parser, Template Parser, and OCR Converter — each with a different data path; Template Parser involves no third-party AI model at all. We never train or enhance any AI or LLM model with your data, and we never sell it. Your data remains exclusively yours and is processed only to deliver the services you request. Read our full AI data-handling explainer for how each engine works.
Data storage and encryption
Data at rest is encrypted using AES-256 and stored in encrypted Amazon S3 buckets. Data in transit is protected end-to-end over HTTPS using modern TLS (TLS 1.2 or higher) and valid digital certificates. Passwords are hashed with bcrypt (work factor 12), a deliberately slow, salted, one-way algorithm—we never have access to your actual password. Payment details never touch our servers—billing is handled by Stripe, a PCI-DSS compliant provider.
Cloud security
Parsio's compute and networking run on Hetzner, with data centers in Falkenstein and Nuremberg, Germany—both certified to ISO/IEC 27001. Data is processed in the EU and US; where required, Standard Contractual Clauses (SCCs) cover the transfer. Hetzner hosts our compute and networking workloads across two independent German locations for redundancy; Amazon S3 is used for encrypted object storage, and application data is stored in MongoDB Atlas. We leverage provider capabilities such as network isolation, granular IAM, key management, and detailed access logging to minimize risk and enforce least-privilege access. Servers communicate over a private network, isolated from the public internet and inaccessible to unauthorized devices.
Availability and resilience
Parsio uses distributed cloud databases and horizontally scalable services to handle load and maintain uptime. We take frequent, automated backups and routinely verify restore procedures to reduce the risk of data loss. Our systems are monitored around the clock with alerting to ensure rapid response to anomalies.
Downtime and scheduled maintenance
We ship changes through CI/CD pipelines and rely on rolling and blue/green deployments to keep updates seamless. Our infrastructure scales dynamically without service shutdowns. When maintenance or incidents occur, we communicate openly via our Status page with real-time availability updates.
Monitoring and logging
We maintain comprehensive system and application logs to support security, reliability, and troubleshooting. Access and key actions are auditable, and customers can review processing activity within the product to understand what happened, when, and by whom.
Data ownership, retention, and deletion
You retain ownership of all emails, documents, and extracted data processed through Parsio. For our parsing services, you act as the Data Controller and Parsio acts as your Data Processor—we process your data strictly according to your instructions. You can delete documents, templates, or your account at any time. Retention policies are configurable to match your legal and business needs, with options typically ranging from 1 to 180 days for automated disposal.
Privacy and confidentiality
We never sell or rent customer data. Employee access is tightly restricted on a need-to-know basis and is governed by confidentiality obligations. Team members receive regular security and privacy training to maintain a strong security culture.
Compliance
Parsio aligns with GDPR requirements. A standard Data Processing Agreement (DPA) is available to all customers, no request needed. Our core compute infrastructure is EU-based (Germany); data is processed in the EU and US, and where a subprocessor operates outside the EU, we rely on appropriate safeguards such as Standard Contractual Clauses. Our infrastructure providers maintain widely recognized certifications (for example, ISO 27001 and SOC 2), which we build upon with our own controls.
Secure development and code management
Security is integrated into our software development lifecycle. Every feature, product update, and bug fix undergoes peer review before release. We perform regular code audits, maintain unit and integration test coverage, and run continuous static analysis, dependency scanning, and automated vulnerability scanning to identify and remediate issues early.
Incident response
We follow documented incident response and escalation procedures. Continuous monitoring helps us detect unusual activity quickly, and if a data breach were to occur, we would notify affected customers and—where required—regulators within 72 hours, in line with GDPR.
Trusted subprocessors
We work with a small number of trusted providers who meet our security and privacy standards and only access the minimum data necessary to provide their services: Amazon S3 (data storage), Amazon Textract (OCR services), Crisp (customer support), Hetzner (cloud infrastructure, Germany, ISO 27001-certified), Microsoft (cloud computing), Mistral (OCR services), MongoDB Atlas (database infrastructure), OpenAI (AI document extraction), and Stripe (payment processing). See our full subprocessors list and AI data-handling explainer for what each one does. We keep this list up to date and communicate material changes.
Questions?
If you have questions about security at Parsio or need more details for your security review, contact us at [email protected].