Security and Trust at Parseur

Parseur protects the documents that run your business, from invoices and purchase orders to bank statements and resumes. Security has been part of how Parseur is built since 2016, and today it's independently verified through a SOC 2 Type II audit.

Try Parseur today
Prefer a guided tour? Book a demo.

Parseur security at a glance

Topic Parseur
SOC 2 Type II Independent audit completed September 2026
Privacy regulations EU GDPR, UK GDPR, Swiss FADP, California CCPA, Singapore PDPA
Encryption At rest and in transit, deprecated protocols disabled
Penetration testing Annually, by an independent security firm
AI training Your data is never used to train AI models that serve anyone else
Data retention Set by you, per mailbox, down to one day
Uptime 99.9% or better, with a public status page
Track record Founded 2016, more than 100 million documents processed

Security training and accountability

Parseur runs a documented information security program covering access management, asset management, change management, data management, secure development, risk management, and vendor management.

Parseur reviews every policy at least once a year and has relevant team members acknowledge it. Parseur performs an annual information security risk assessment, reviews staff access to systems at least annually, and follows documented onboarding, off-boarding, and reference-check procedures. Everyone who handles personal data is bound by confidentiality obligations and receives training on their data protection responsibilities.

SOC 2 Type II report

Parseur completed a SOC 2 Type II examination conducted by independent auditor Constellation GRC. Parseur announced the successful completion of the audit on 8 September 2026.

A SOC 2 Type II report is an auditor's opinion on whether security controls actually operated effectively over a period of time, not just whether they were designed well on paper. It covers the controls behind the Parseur document processing platform. SOC 2 is an attestation rather than a certificate, so the report itself is the proof, and you can request it through the Parseur Trust Center.

Compliance with data privacy regulations

Parseur complies with the major data privacy laws that govern how our customers' data is handled:

  • GDPR: the EU General Data Protection Regulation
  • UK GDPR: the United Kingdom's version, alongside the Data Protection Act 2018
  • Swiss FADP: the Federal Act on Data Protection
  • CCPA: the California Consumer Privacy Act
  • Singapore PDPA: the Personal Data Protection Act of Singapore, where Parseur is incorporated

You retain control of the data you send to Parseur. When you act as the data controller, Parseur acts as your data processor. If you process data on behalf of another organization, Parseur may act as your sub-processor.

Parseur never sells customer data or shares it for advertising or unrelated commercial purposes. Parseur only uses a limited set of sub-processors, selected after careful vetting, where necessary to provide and secure the service.

Our data processing agreement is published in full, so your legal team can review it before anyone books a call. Parseur has appointed DataRep as its representative in the EU, UK and Switzerland.

Request our SOC 2 report
Want to walk through it with our team? Book a demo.

Penetration testing and vulnerability management

An independent security firm performs a penetration test of Parseur every year.

Between tests, Parseur runs continuous automated scanning of its production infrastructure, static analysis of its application code, and monitoring of every third-party dependency for newly disclosed vulnerabilities. Parseur also tests its application, API, and infrastructure against widely recognized security risk frameworks, including the OWASP Top 10 and the CWE Top 25 Most Dangerous Software Weaknesses. Parseur fixes vulnerabilities within severity-based timeframes, under a documented vulnerability and patch management policy.

Encryption and data protection

Parseur encrypts all customer data at rest and in transit.

Traffic between you, Parseur, and your connected integrations uses modern transport-layer encryption, with deprecated protocols disabled. Parseur runs on major cloud providers whose data centers hold independent security attestations such as ISO 27001 or SOC 2 Type 2, with strict physical access controls and monitored security zones. Infrastructure is managed as code and version-controlled, application secrets are kept in access-controlled secret management systems separate from source code, and every production change is peer-reviewed and tested before release. Each customer's data is logically segregated from every other customer's.

Access control and account security

Access to customer data at Parseur follows least-privilege and need-to-know principles.

Parseur staff use multi-factor authentication for production systems and administrative interfaces, and administrative access to production goes through a managed access gateway with key-based authentication. Document processing is automated, so the team accesses your data only to support you or resolve a technical issue.

In your own account, you can enable multi-factor authentication or single sign-on, and invite teammates with roles and permissions so each person sees only what they need. Parseur never stores passwords in plain text. Parseur hashes passwords using PBKDF2 with SHA-256, a 512-bit salt, and 1,000,000 iterations. This exceeds the current OWASP recommendation of 600,000 or more iterations for PBKDF2-HMAC-SHA-256.

Devices

Parseur centrally manages every team device that can access personal data.

Managed devices enforce disk encryption, anti-malware protection, and automatic screen locking. If a laptop is lost or stolen, the data on it stays unreadable.

Data retention and deletion

With Parseur, you control how long documents are retained, with retention settings available per mailbox. The available maximum retention period depends on your Parseur plan, ranging from shorter retention periods to unlimited retention on eligible plans.

Set retention per mailbox, directly in the app, with no minimum period and no support ticket required. Set a mailbox to 24 hours, and your documents are deleted after 24 hours. With Process then Delete, Parseur removes a document from its servers as soon as it sends you the extracted data.

You can export and permanently erase your data at any time with built-in tools. If you close your account, Parseur deletes all copies of your data within 45 days, and automatically deletes accounts inactive for more than a year.

AI and your documents

Parseur does not use customer documents to train AI models for other customers or third parties.

This protection is included in clause 4.10 of our Data Processing Agreement, which prohibits using customer personal data to train or improve AI or machine-learning models that provide services to other parties.

Parseur also does not use customer documents to train its own AI models. And if your organization does not want AI-based extraction involved at all, you can use Parseur's template-based extraction features instead.

Data processing, storage and transfers

Data collected by Parseur may be transferred to, stored, and processed in the European Union.

Parseur's application data, except payment details, is stored in the EU on Google Cloud and Microsoft infrastructure, with a subset of documents processed by Scaleway in France. Incoming email depends on your mailbox address: emails sent to @eu.parseur.com addresses are received by Mailgun with EU storage, while emails sent to @in.parseur.com addresses are received by Postmark in the United States.

Where data crosses borders, transfers are protected by the EU-US Data Privacy Framework and Standard Contractual Clauses, with the UK Addendum and Swiss adjustments built into our DPA.

Vendor and sub-processor management

Parseur works with five sub-processors, and it names each one publicly.

Before a vendor can touch customer data, Parseur reviews its security and privacy posture and puts a data processing agreement in place that commits it to the same confidentiality and security standards we commit to you.

The sub-processor list includes each provider's data categories, transfer mechanisms and contact details.

Incident response and breach notification

If Parseur discovers a breach affecting your personal data, we notify you without undue delay and within 48 hours.

We monitor our systems continuously, and we review access rights to customer data as part of our SOC 2 controls. If you suspect a security issue with your account, contact [email protected] immediately.

Reliability and business continuity

Parseur has run in production since 2016 and has processed more than 100 million documents. We target 99.9% or higher uptime, measured over a trailing 12-month period.

We publish live uptime and full incident history on the Parseur status page. If Parseur were ever unavailable, incoming emails wouldn't be lost. Our email collection platform retries delivery for up to 24 hours, and dual sending adds a second delivery path for extra redundancy.

Security and procurement resources

Everything your security review needs, available before you talk to sales:

Ready to automate document processing securely?

See why teams trust Parseur with over 100 million documents, from invoices to bills of lading.

Try Parseur today
Prefer a guided tour? Book a demo.

Reporting a security vulnerability

Parseur welcomes reports from security researchers and works with them to fix issues responsibly.

How to report. If you believe you've found a security vulnerability in Parseur, email [email protected] with a description of the issue, the steps to reproduce it, the affected URL or API endpoint, and any proof of concept. Clear, reproducible reports get investigated fastest.

Not in scope. The following security issues are currently not in scope (please don't report them):

  • Volumetric vulnerabilities (i.e. simply overwhelming our service with a high volume of requests).
  • Reports of non-exploitable vulnerabilities.
  • Reports indicating that our services do not fully align with "best practice" or other cosmetic recommendations.

If reported, we will ignore these reports and may block the reporter.

What happens next. We read every report and investigate every legitimate one. We'll acknowledge your report, keep you updated during the investigation, and fix confirmed issues as quickly as possible.

Disclosure and credit. We don't disclose issues until our investigation is complete and we have a fix in place. Once we resolve an issue, we publish a security update in our changelog and, if you'd like, thank you and credit you for the discovery.

Last updated on

Get started

Ready to automate your
document data extraction?

Start free in minutes and see how Parseur fits into your workflow.

No model training required
Automates data entry from any document
Scales from point-and-click to API

Frequently asked questions

Quick answers for the security, legal, and procurement teams reviewing Parseur.

Yes. Parseur has successfully completed a SOC 2 Type II examination conducted by independent auditor Constellation GRC. Parseur announced completion on 8 September 2026. Eligible customers can request access to the SOC 2 Type II report through the Parseur Trust Center.

Yes. Parseur's legal terms, policies, and practices comply with the California Consumer Privacy Act. Parseur never sells customer data.

Yes. Parseur is a Singapore company and complies with Singapore's Personal Data Protection Act.

Parseur stores and processes application data in the European Union. All application data except payment details is stored in the EU on Google Cloud and Microsoft infrastructure, with a subset of documents processed by Scaleway in France. Emails sent to @eu.parseur.com addresses are received by Mailgun with EU storage, while emails sent to @in.parseur.com addresses are received by Postmark in the United States.

As long as you choose, from one day up to the maximum retention period of your plan, which is unlimited on eligible plans. Retention is configurable per mailbox in the app, and Process then Delete removes documents as soon as Parseur sends the extracted data to you.

Yes. An independent cybersecurity firm tests Parseur every year. In between, the application, API, and infrastructure are continuously tested against the OWASP Top 10 and the CWE Top 25.

Parseur publishes pre-written answers to common security questionnaire questions so you can complete most reviews without waiting on us. For Enterprise customers, Parseur completes the full questionnaire.

99.9% or better, published live with full incident history on the Parseur status page.

Yes. Parseur complies with the EU GDPR and UK GDPR and has maintained GDPR-aligned data protection practices since the regulation became applicable in May 2018. Parseur publishes its Data Processing Agreement so customers and legal teams can review its privacy and data processing commitments directly.

Yes. Parseur complies with Switzerland's Federal Act on Data Protection.

Not yet. HIPAA compliance is in progress, and Parseur doesn't sign Business Associate Agreements today. If you process protected health information, contact us, and we'll tell you honestly where things stand.

No. Parseur does not use customer documents to train its AI models, and it does not use customer data to train models that serve other customers or third parties. This protection is also written into Parseur's Data Processing Agreement, which prohibits using customer personal data to train or improve AI models that provide services to other parties.

Parseur encrypts all customer data at rest and in transit, and disables deprecated transport protocols. Parseur encrypts backups and stores them in geographically separate locations, isolated from production.

Google Cloud, Scaleway, Microsoft, Mailgun, and ActiveCampaign (Postmark). The sub-processor list details each one's purpose, location, and transfer mechanism.

Request access through the Parseur Trust Center.