Parseur protects the documents that run your business, from invoices and purchase orders to bank statements and resumes. Security has been part of how Parseur is built since 2016, and today it's independently verified through a SOC 2 Type II audit.
Parseur security at a glance
| Topic | Parseur |
|---|---|
| SOC 2 Type II | Independent audit completed September 2026 |
| Privacy regulations | EU GDPR, UK GDPR, Swiss FADP, California CCPA, Singapore PDPA |
| Encryption | At rest and in transit, deprecated protocols disabled |
| Penetration testing | Annually, by an independent security firm |
| AI training | Your data is never used to train AI models that serve anyone else |
| Data retention | Set by you, per mailbox, down to one day |
| Uptime | 99.9% or better, with a public status page |
| Track record | Founded 2016, more than 100 million documents processed |
Security training and accountability
Parseur runs a documented information security program covering access management, asset management, change management, data management, secure development, risk management, and vendor management.
Parseur reviews every policy at least once a year and has relevant team members acknowledge it. Parseur performs an annual information security risk assessment, reviews staff access to systems at least annually, and follows documented onboarding, off-boarding, and reference-check procedures. Everyone who handles personal data is bound by confidentiality obligations and receives training on their data protection responsibilities.
SOC 2 Type II report
Parseur completed a SOC 2 Type II examination conducted by independent auditor Constellation GRC. Parseur announced the successful completion of the audit on 8 September 2026.
A SOC 2 Type II report is an auditor's opinion on whether security controls actually operated effectively over a period of time, not just whether they were designed well on paper. It covers the controls behind the Parseur document processing platform. SOC 2 is an attestation rather than a certificate, so the report itself is the proof, and you can request it through the Parseur Trust Center.
Compliance with data privacy regulations
Parseur complies with the major data privacy laws that govern how our customers' data is handled:
- GDPR: the EU General Data Protection Regulation
- UK GDPR: the United Kingdom's version, alongside the Data Protection Act 2018
- Swiss FADP: the Federal Act on Data Protection
- CCPA: the California Consumer Privacy Act
- Singapore PDPA: the Personal Data Protection Act of Singapore, where Parseur is incorporated
You retain control of the data you send to Parseur. When you act as the data controller, Parseur acts as your data processor. If you process data on behalf of another organization, Parseur may act as your sub-processor.
Parseur never sells customer data or shares it for advertising or unrelated commercial purposes. Parseur only uses a limited set of sub-processors, selected after careful vetting, where necessary to provide and secure the service.
Our data processing agreement is published in full, so your legal team can review it before anyone books a call. Parseur has appointed DataRep as its representative in the EU, UK and Switzerland.
Penetration testing and vulnerability management
An independent security firm performs a penetration test of Parseur every year.
Between tests, Parseur runs continuous automated scanning of its production infrastructure, static analysis of its application code, and monitoring of every third-party dependency for newly disclosed vulnerabilities. Parseur also tests its application, API, and infrastructure against widely recognized security risk frameworks, including the OWASP Top 10 and the CWE Top 25 Most Dangerous Software Weaknesses. Parseur fixes vulnerabilities within severity-based timeframes, under a documented vulnerability and patch management policy.
Encryption and data protection
Parseur encrypts all customer data at rest and in transit.
Traffic between you, Parseur, and your connected integrations uses modern transport-layer encryption, with deprecated protocols disabled. Parseur runs on major cloud providers whose data centers hold independent security attestations such as ISO 27001 or SOC 2 Type 2, with strict physical access controls and monitored security zones. Infrastructure is managed as code and version-controlled, application secrets are kept in access-controlled secret management systems separate from source code, and every production change is peer-reviewed and tested before release. Each customer's data is logically segregated from every other customer's.
Access control and account security
Access to customer data at Parseur follows least-privilege and need-to-know principles.
Parseur staff use multi-factor authentication for production systems and administrative interfaces, and administrative access to production goes through a managed access gateway with key-based authentication. Document processing is automated, so the team accesses your data only to support you or resolve a technical issue.
In your own account, you can enable multi-factor authentication or single sign-on, and invite teammates with roles and permissions so each person sees only what they need. Parseur never stores passwords in plain text. Parseur hashes passwords using PBKDF2 with SHA-256, a 512-bit salt, and 1,000,000 iterations. This exceeds the current OWASP recommendation of 600,000 or more iterations for PBKDF2-HMAC-SHA-256.
Devices
Parseur centrally manages every team device that can access personal data.
Managed devices enforce disk encryption, anti-malware protection, and automatic screen locking. If a laptop is lost or stolen, the data on it stays unreadable.
Data retention and deletion
With Parseur, you control how long documents are retained, with retention settings available per mailbox. The available maximum retention period depends on your Parseur plan, ranging from shorter retention periods to unlimited retention on eligible plans.
Set retention per mailbox, directly in the app, with no minimum period and no support ticket required. Set a mailbox to 24 hours, and your documents are deleted after 24 hours. With Process then Delete, Parseur removes a document from its servers as soon as it sends you the extracted data.
You can export and permanently erase your data at any time with built-in tools. If you close your account, Parseur deletes all copies of your data within 45 days, and automatically deletes accounts inactive for more than a year.
AI and your documents
Parseur does not use customer documents to train AI models for other customers or third parties.
This protection is included in clause 4.10 of our Data Processing Agreement, which prohibits using customer personal data to train or improve AI or machine-learning models that provide services to other parties.
Parseur also does not use customer documents to train its own AI models. And if your organization does not want AI-based extraction involved at all, you can use Parseur's template-based extraction features instead.
Data processing, storage and transfers
Data collected by Parseur may be transferred to, stored, and processed in the European Union.
Parseur's application data, except payment details, is stored in the EU on Google Cloud and Microsoft infrastructure, with a subset of documents processed by Scaleway in France. Incoming email depends on your mailbox address: emails sent to @eu.parseur.com addresses are received by Mailgun with EU storage, while emails sent to @in.parseur.com addresses are received by Postmark in the United States.
Where data crosses borders, transfers are protected by the EU-US Data Privacy Framework and Standard Contractual Clauses, with the UK Addendum and Swiss adjustments built into our DPA.
Vendor and sub-processor management
Parseur works with five sub-processors, and it names each one publicly.
Before a vendor can touch customer data, Parseur reviews its security and privacy posture and puts a data processing agreement in place that commits it to the same confidentiality and security standards we commit to you.
The sub-processor list includes each provider's data categories, transfer mechanisms and contact details.
Incident response and breach notification
If Parseur discovers a breach affecting your personal data, we notify you without undue delay and within 48 hours.
We monitor our systems continuously, and we review access rights to customer data as part of our SOC 2 controls. If you suspect a security issue with your account, contact [email protected] immediately.
Reliability and business continuity
Parseur has run in production since 2016 and has processed more than 100 million documents. We target 99.9% or higher uptime, measured over a trailing 12-month period.
We publish live uptime and full incident history on the Parseur status page. If Parseur were ever unavailable, incoming emails wouldn't be lost. Our email collection platform retries delivery for up to 24 hours, and dual sending adds a second delivery path for extra redundancy.
Security and procurement resources
Everything your security review needs, available before you talk to sales:
- SOC 2 Type II report: request access through the Trust Center
- Data processing agreement: published in full
- Sub-processor list: every vendor, location, and transfer mechanism
- Answers to security questionnaires: pre-written answers to the questions procurement teams ask most
- Privacy policy, GDPR at Parseur and status page
Ready to automate document processing securely?
See why teams trust Parseur with over 100 million documents, from invoices to bills of lading.
Reporting a security vulnerability
Parseur welcomes reports from security researchers and works with them to fix issues responsibly.
How to report. If you believe you've found a security vulnerability in Parseur, email [email protected] with a description of the issue, the steps to reproduce it, the affected URL or API endpoint, and any proof of concept. Clear, reproducible reports get investigated fastest.
Not in scope. The following security issues are currently not in scope (please don't report them):
- Volumetric vulnerabilities (i.e. simply overwhelming our service with a high volume of requests).
- Reports of non-exploitable vulnerabilities.
- Reports indicating that our services do not fully align with "best practice" or other cosmetic recommendations.
If reported, we will ignore these reports and may block the reporter.
What happens next. We read every report and investigate every legitimate one. We'll acknowledge your report, keep you updated during the investigation, and fix confirmed issues as quickly as possible.
Disclosure and credit. We don't disclose issues until our investigation is complete and we have a fix in place. Once we resolve an issue, we publish a security update in our changelog and, if you'd like, thank you and credit you for the discovery.
Last updated on