docIQHelp Center
Help CenterTrust and safety

Trust and safety

Security, privacy, and responsible use

Understand isolation, document handling, support access, and your organization’s responsibilities.

Data boundaries

Customer content is scoped by tenant, workspace, and project. Tenant identity comes from verified authentication, and database row-level security enforces the tenant boundary. Object-storage and background-work keys are also namespaced to the same scope.

Document protection

  • Files are scanned before parsing.
  • Stored objects are private and addressed through tenant- and project-scoped keys.
  • Document access is checked before a short-lived download or preview link is issued.
  • Application logs exclude document content, prompts containing content, secrets, and unredacted personal data.
  • Documents are treated as hostile evidence and never as instructions to the analysis system.

Support access

Platform support does not use an ordinary customer request path to browse content. When authorized support access is required, it is reason-tagged and audited, and the affected tenant can review the event.

Your responsibilities

  • Upload only data you are authorized to process.
  • Use project membership to limit sensitive evidence to the review team.
  • Remove access promptly when responsibilities change.
  • Follow applicable retention, employment, procurement, privacy, and sector-specific rules.
  • Have a qualified person verify high-impact findings and citations before acting.

Report a concern

If you suspect unauthorized access or a security issue, stop sharing affected reports, preserve the time and correlation ID, and contact your DocIQ administrator or support channel. Do not include passwords, access tokens, or document contents in the initial report.