Trust and security
How Includoc stores, protects and deletes your documents: US storage, encryption, short retention, isolated processing and no AI training on your files.
Last updated

Public agencies, colleges and consultants send us documents that often contain names, addresses and other personal details. This page explains, in plain terms, how we handle them. For the contract terms behind it, see our data processing addendum and privacy policy.
The short version
- Your documents are stored and processed in the United States.
- Files are encrypted in transit and at rest.
- Files you check without an account are deleted within 24 hours. Files in an account are deleted after 30 days by default.
- Documents are opened only inside isolated processing containers that hold no API keys.
- AI processing runs through providers that don't keep your files or train on them.
- We don't accept protected health information until a business associate agreement chain is in place.
How a file moves through Includoc
- Upload. Your browser sends the file straight to our storage (Cloudflare R2) through a one-time upload link that expires after 5 minutes. The file never passes through our website's servers.
- Queue. Our backend (Convex) confirms the upload arrived intact and queues a job.
- Check. An isolated processing container downloads the file through a short-lived link, scans it for malware, and checks it with veraPDF and our own tests. It writes results and page images back to storage the same way.
- Fix. If you've asked for a fix, our backend sends page images and structure information to an AI model and validates every response before using it. The container then applies the corrections, re-validates the file and writes the fixed file and reports to storage.
- Download. You get your results through links that expire after 5 minutes.
If you paste a link to a public document instead of uploading it, our fetcher, IncludocBot, downloads that one file and the same steps follow.
Where your documents live
We store documents in Cloudflare R2. Documents are stored and processed in the United States.
Our storage buckets are private. There are no public links to your files, and every upload or download link is signed and expires after 5 minutes.
Encryption
Every connection to Includoc uses TLS (HTTPS). Files are encrypted at rest in storage, and our database provider encrypts data at rest.
How long we keep things
We keep your documents only as long as you need them:
- Checks without an account: the file is deleted within 24 hours. Results stay available for 30 days so you can come back to them, or until you sign up and claim them.
- Files in an account: deleted 30 days after upload by default. Organization admins can choose 7, 30, 90 or 365 days.
- Fixed files: deleted on the same schedule as the original.
- Shared result links: expire after 30 days.
- Reports and records: what was checked, the results, and who approved what and when are kept for your audit trail. These records don't include your document's content.
Delete now. You can delete a file at any time. "Delete now" removes the original, the fixed files and the page images from storage right away, removes document content from our records, and notes the deletion in your audit log. Copies in our database backups expire on their normal schedule.
Isolated processing
We only open documents inside isolated processing containers. Each container:
- Runs one job at a time, as a non-root user
- Has a read-only file system, apart from temporary space for the job
- Has hard limits on processing time and memory
- Can reach only our storage and our backend
- Holds no API keys
Each job arrives with short-lived links to just the files it needs and a job token that works only for that job. Every message between a container and our backend is signed, so neither side accepts a message the other didn't send. Every upload is scanned for malware before processing.
Keys and secrets
Every API key and secret we use lives in our backend's secret store. None of them are in our website code or your browser, and none are built into our container images. The processing containers and the crawler hold a single signing secret, used only to verify jobs and sign their replies. We use separate keys for development and production, rotate high-value keys on a schedule, and scan our code for leaked secrets.
AI processing
When you fix a document, our backend sends page images, cropped images of figures, and text and structure information to an AI model. The model suggests headings, reading order, table headers and alt text.
- Requests go through OpenRouter and are routed only to Anthropic's Claude models.
- We use zero-data-retention routing, refuse providers that collect data, turn off prompt logging and opt out of training.
- Your files are never used to train AI models.
- AI calls run only in our backend, never from your browser or the processing containers.
- Every AI response is checked against a strict format before we use it. Low-confidence suggestions are flagged for a person to review, never applied silently.
We don't use your files to improve Includoc unless you explicitly agree. Quality audits of customer files happen only with permission.
People and access
Only a small number of authorized people can reach our production systems. Every vendor account we use is protected with multi-factor authentication. Access follows least privilege and is reviewed every quarter. When our support team looks at an account to help you, that access is read-only and logged.
If you order human verification, a vetted accessibility specialist who is bound by confidentiality opens your document to review it. They see only the files assigned to them.
Your organization's audit log records who uploaded, fixed, approved, exempted and deleted what, and when. Entries can't be edited.
Health information
Includoc isn't yet set up to handle protected health information (PHI). Our terms don't allow uploading PHI unless we've signed a business associate agreement (BAA) with you. We won't offer BAAs until every provider that would touch PHI has signed one with us. Healthcare organizations confirm a no-PHI notice before uploading. To hear when that changes, join the healthcare waitlist.
Reporting a vulnerability
If you think you've found a security problem, email security@includoc.com. Our security.txt file lists the same contact.
Please include the steps to reproduce the problem, don't access or change other people's data, and give us reasonable time to fix it before sharing details publicly. We'll confirm we've received your report and keep you updated on our progress.
If something goes wrong
We keep an incident response plan. If we confirm a security incident that affects your data, we'll notify you within 72 hours of confirming it. We'll explain what happened, what data was involved and what we're doing about it, and we'll keep you updated until it's resolved. You can check the status of our service at any time on our status page (opens another website).
Subprocessors
We use a small set of providers to run Includoc, including Cloudflare for storage and processing, Convex for our backend, and OpenRouter and Anthropic for AI. The full list, with what each provider does and where it processes data, is on our subprocessors page. We announce changes there before they take effect.
Documents for your procurement team
- Data processing addendum
- Terms of service, privacy policy and acceptable use policy
- On request: our W-9, certificate of insurance and security overview, and our Accessibility Conformance Report (ACR) once it's published. Request documents, and send your security questionnaire with the request if you have one.
At a glance
Data flow diagram
- Your browser loads our website from Vercel. Vercel only holds public keys, never secrets.
- Your browser talks to our backend on Convex, which holds every API key and secret. It gives your browser a short-lived link (5 minutes) to upload a file.
- Your browser uploads the file straight to encrypted storage on Cloudflare R2 in the United States.
- Convex sends a job to an isolated processing container. The container has no API keys; it reads and writes files only through short-lived links for that job, and reports back with a signed message.
- When you fix a document, Convex sends page images and text to AI models through OpenRouter, pinned to Anthropic with zero data retention. Your files are never used to train AI.
Retention schedule
| Data | How long we keep it |
|---|---|
| Files uploaded without an account | Deleted within 24 hours |
| Results for checks without an account | 30 days, unless you claim them by signing up |
| Files uploaded to an account (originals and fixed files) | 30 days by default. Organizations can choose 7, 30, 90, 365 days. Anyone can delete a file right away. |
| Share links to results | Expire after 30 days |
| Reports and check results (no document text beyond short issue snippets) | For the life of the account plus one year, as an audit trail |
| Account details | For the life of the account |
| Payment details | Held by Stripe. We never store card numbers. |
| Product analytics | Pseudonymous, 12 months. Session recording is off. |
Subprocessor list
These companies process data for us. We’ll add our document-tagging vendor before we use one, and WorkOS when single sign-on launches, with notice before either processes customer data. For where each one processes data, see the subprocessors page.
| Company | What they do for us | Data they handle |
|---|---|---|
| Vercel | Hosts our website | Web requests (IP address, browser details) |
| Convex | Database and backend | Account data, check results, job records |
| Cloudflare | File storage (R2), document processing, bot protection (Turnstile), DNS | Uploaded and fixed documents |
| OpenRouter | Routes AI requests to the model provider | Page images and text sent for fixing |
| Anthropic | AI model provider (through OpenRouter) | Page images and text sent for fixing |
| Stripe | Payments, invoices and tax | Billing contacts and payment details |
| Resend | Email delivery | Email addresses and message content |
| Sentry | Error monitoring | Technical error reports |
| PostHog | Product analytics | Pseudonymous usage events |
| Better Stack | Uptime monitoring and status page | No customer content |
Procurement documents
- Data processing agreement (DPA): Read online
- W-9: Available on request
- Certificate of insurance: Available on request
- Security overview (PDF): Available on request
- Accessibility Conformance Report (ACR / VPAT 2.5): Available on request
Need a security questionnaire completed? Ask us. Invoices can carry a purchase order number, with net-30 terms and ACH, wire or check payment.
Security contacts and status
- Report a security issue: security@includoc.com (see our security.txt). If an incident affects your data, we’ll notify you within 72 hours of confirming it.
- Service status: status.includoc.com (opens another website)
Related
- Subprocessors
The providers Includoc uses to run its service, what each one does, the data it handles, where it processes data, and how we notify you of changes.
- Data Processing Addendum
How Includoc processes personal data for customers: roles, instructions, security, subprocessors, breach notice, deletion, audits and data transfers.
- Privacy Policy
What personal information Includoc collects, why we collect it, how long we keep it, who processes it for us, and the choices and rights you have.
- Accessibility statement
Our goal for Includoc's own accessibility: WCAG 2.2 AA, how we test with screen readers and keyboards, known issues, and how to tell us about a problem.