How Secure Is DocuClipper?
Encryption in transit and at rest, SOC 2 Type II, the Intuit App Store review, access controls, and data retention: how DocuClipper protects financial data.
Last updated
DocuClipper encrypts customer data in transit (TLS) and at rest, maintains a SOC 2 Type II report, and passes the Intuit App Store security review for its QuickBooks integration. Customer documents are never used to train AI models and are never sold to third parties.
Role-based access controls (Read / Write / Admin) apply at the folder level, SSO is available on Enterprise plans, and your data stays in your account while your subscription is active.
What encryption does DocuClipper use?
- In transit: all connections are served over HTTPS (TLS 1.2+). No unencrypted endpoints are exposed.
- At rest: documents and extracted data are stored encrypted (AES-256) on SOC 2-compliant AWS infrastructure.
- Backups are encrypted.
Compliance and reviews
- SOC 2 Type II: DocuClipper maintains a SOC 2 Type II report (security program managed in Vanta). The report is available under NDA — email security@docuclipper.com.
- Intuit App Store review: DocuClipper's QuickBooks integration is reviewed by Intuit as part of App Store certification.
- GDPR: EU data subject requests (access, deletion, export) are supported. Contact support from your account email.
- Enterprise security questionnaires and NDAs: available on request for Business and Enterprise plans.
Access controls
- Role-based access (Read / Write / Admin) at the folder level.
- SSO available on Enterprise plans.
- Password reset flows use signed, time-limited tokens.
- No DocuClipper employee has routine access to customer data; support access is limited and logged.
Data retention and deletion
- While your subscription is active, your jobs stay in your account — DocuClipper does not age them out.
- On free, trial, or lapsed (unpaid) accounts, jobs older than 30 days are automatically deleted.
- After you cancel, extracted documents and data are kept for a grace period and then permanently deleted; lightweight settings (templates, tags, integration mappings) are retained so reactivation is friction-free. See Jobs are missing.
- You can delete any job manually at any time from the job's actions menu. Manual deletion is permanent.
What DocuClipper does NOT do
- We do not sell or share customer data with third parties.
- We do not use customer financial documents to train AI models.
Policies
For a security questionnaire or our SOC 2 report, email security@docuclipper.com.
FAQs
Is DocuClipper SOC 2 compliant?
Yes. DocuClipper maintains a SOC 2 Type II report (security program managed in Vanta), available under NDA. Separately, the QuickBooks integration is reviewed by Intuit as part of App Store certification.
How is my data encrypted?
All connections use TLS 1.2 or higher in transit, and documents and extracted data are stored with AES-256 encryption at rest on SOC 2-compliant AWS infrastructure. Backups are encrypted.
Does DocuClipper use my documents to train AI models?
No. DocuClipper does not use customer financial documents to train AI models and does not sell or share customer data with third parties.
How long does DocuClipper keep my data?
While your subscription is active, your jobs stay in your account. On free, trial, or unpaid accounts, jobs older than 30 days are deleted automatically. After you cancel, extracted data is kept for a grace period and then permanently deleted, while lightweight settings are retained in case you reactivate. You can also delete any job manually at any time.
Can DocuClipper employees see my documents?
No employee has routine access to customer data. Support access is limited and every access event is logged.
Is DocuClipper GDPR compliant?
Yes. EU data subject requests for access, deletion, and export are supported. Contact support from your account email to file a request.