We appreciate your confidence and work hard to keep your information secure.
Security at Parsio
At Parsio, the security of your data is foundational to how we design, build, and operate our platform. We combine strong technical controls with disciplined operational practices to protect confidentiality, integrity, and availability.
EU-hosted in Germany
AES-256 at rest, TLS 1.2+ in transit
Your data never trains AI models
GDPR-compliant, DPA available
Quick answers
Where is my data physically stored?
Parsio's core infrastructure — compute, networking, and storage — runs on Hetzner, with data centers in Falkenstein and Nuremberg, Germany. Both sites are certified to ISO/IEC 27001. Documents and exports live in encrypted Amazon S3 buckets; application data lives in MongoDB Atlas.
Is my data used to train AI models?
Never. We don't train or fine-tune any model — ours or our providers' — on your data, and we never sell it. This is a contractual commitment with every AI subprocessor we use, not a plan-dependent feature.
How are my passwords protected?
Passwords are hashed with bcrypt using a work factor of 12 — a deliberately slow, salted, one-way algorithm designed to resist brute-force and rainbow-table attacks. We never store or have access to your actual password.
What encryption do you use?
TLS 1.2+ with valid certificates for everything in transit, and AES-256 for everything at rest, including document storage and database backups.
Is Parsio GDPR-compliant?
Yes. For parsing services, you're the Data Controller and Parsio is your Data Processor. A standard Data Processing Agreement (DPA) is available to all customers, no request needed, and our primary infrastructure is EU-based, so most processing doesn't require an international transfer mechanism at all. Where an AI subprocessor is US-based, Standard Contractual Clauses (SCCs) cover the transfer. See our GDPR page and DPA.
What happens if there's a security breach?
We continuously monitor for unusual activity and follow documented incident-response procedures. If a breach occurs, affected customers and relevant authorities are notified within 72 hours where required by law.
How do you find and fix vulnerabilities?
Every code change goes through peer review before release. We run continuous static analysis, dependency scanning, and automated vulnerability scanning across our infrastructure and codebase, backed by unit/integration tests and automated pipelines that guard against regressions.
Can I delete my data?
Yes, at any time — individual documents, templates, or your entire account. Data is removed from active systems immediately and from backups/logs within your configured retention window. You can also set automatic deletion between 1 and 180 days.
Who can access my data inside Parsio?
Access is restricted to what's strictly necessary (least privilege) and audited regularly. All employees complete security and privacy training and are bound by confidentiality obligations.
Do you sell or share my data?
No — never, under any circumstances, without your consent. Your documents, emails, and extracted data are yours.
What's your uptime?
Track live availability and incident history on our status page.
AI and data use
Parsio offers four parsing engines — AI Parser, GPT Parser, Template Parser, and OCR Converter — each with a different data path; Template Parser involves no third-party AI model at all. We never train or enhance any AI or LLM model with your data, and we never sell it. Your data remains exclusively yours and is processed only to deliver the services you request. Read our full AI data-handling explainer for how each engine works.
Data storage and encryption
Data at rest is encrypted using AES-256 and stored in encrypted Amazon S3 buckets. Data in transit is protected end-to-end over HTTPS using modern TLS (TLS 1.2 or higher) and valid digital certificates. Passwords are hashed with bcrypt (work factor 12), a deliberately slow, salted, one-way algorithm—we never have access to your actual password. Payment details never touch our servers—billing is handled by Stripe, a PCI-DSS compliant provider.
Cloud security
Parsio's core infrastructure runs on Hetzner, with data centers in Falkenstein and Nuremberg, Germany—both certified to ISO/IEC 27001. Since our primary infrastructure is EU-based, most processing doesn't require an international data transfer mechanism at all. Hetzner hosts our compute and networking workloads across two independent German locations for redundancy; Amazon S3 is used for encrypted object storage, and application data is stored in MongoDB Atlas. We leverage provider capabilities such as network isolation, granular IAM, key management, and detailed access logging to minimize risk and enforce least-privilege access.
Availability and resilience
Parsio uses distributed cloud databases and horizontally scalable services to handle load and maintain uptime. We take frequent, automated backups and routinely verify restore procedures to reduce the risk of data loss. Our systems are monitored around the clock with alerting to ensure rapid response to anomalies.
Downtime and scheduled maintenance
We ship changes through CI/CD pipelines and rely on rolling and blue/green deployments to keep updates seamless. Our infrastructure scales dynamically without service shutdowns. When maintenance or incidents occur, we communicate openly via our Status page with real-time availability updates.
Monitoring and logging
We maintain comprehensive system and application logs to support security, reliability, and troubleshooting. Access and key actions are auditable, and customers can review processing activity within the product to understand what happened, when, and by whom.
Data ownership, retention, and deletion
You retain ownership of all emails, documents, and extracted data processed through Parsio. For our parsing services, you act as the Data Controller and Parsio acts as your Data Processor—we process your data strictly according to your instructions. You can delete documents, templates, or your account at any time. Retention policies are configurable to match your legal and business needs, with options typically ranging from 1 to 180 days for automated disposal.
Privacy and confidentiality
We never sell or rent customer data. Employee access is tightly restricted on a need-to-know basis and is governed by confidentiality obligations. Team members receive regular security and privacy training to maintain a strong security culture.
Compliance
Parsio aligns with GDPR requirements. A standard Data Processing Agreement (DPA) is available to all customers, no request needed. Because our primary infrastructure is EU-based, most processing doesn't require an international transfer mechanism; where it does—for example, with a US-based AI subprocessor—we rely on appropriate safeguards such as Standard Contractual Clauses. Our infrastructure providers maintain widely recognized certifications (for example, ISO 27001 and SOC 2), which we build upon with our own controls.
Secure development and code management
Security is integrated into our software development lifecycle. Every feature, product update, and bug fix undergoes peer review before release. We perform regular code audits, maintain unit and integration test coverage, and run continuous static analysis, dependency scanning, and automated vulnerability scanning to identify and remediate issues early.
Incident response
We follow documented incident response and escalation procedures. Continuous monitoring helps us detect unusual activity quickly, and if a data breach were to occur, we would notify affected customers and—where required—regulators within 72 hours, in line with GDPR.
Trusted subprocessors
We work with a small number of trusted providers who meet our security and privacy standards and only access the minimum data necessary to provide their services: Amazon S3 (data storage), Amazon Textract (OCR services), Crisp (customer support), Hetzner (cloud infrastructure, Germany, ISO 27001-certified), Microsoft (cloud computing), Mistral (OCR services), MongoDB Atlas (database infrastructure), OpenAI (AI document extraction), and Stripe (payment processing). See our full subprocessors list and AI data-handling explainer for what each one does. We keep this list up to date and communicate material changes.
Questions?
If you have questions about security at Parsio or need more details for your security review, contact us at [email protected].