Trust · Security
Security and data handling
How pilot documents are stored, who can reach them, what is logged, and what deletion removes. Written for the reviewer and the operator sitting beside them.
- Documents live in an isolated store scoped to a single customer and review; every access is authorized server-side against that ownership chain.
- Connections to ProcureTrace are encrypted in transit (TLS), and documents and review data are stored on infrastructure that encrypts data at rest.
- Uploads are validated (type allowlist, size limits, content checks), stored under generated names, never executed, and never modified. The original bytes are what your reviewer can re-download.
- Automated document reading uses cloud document-analysis and AI services (Microsoft Azure) under ProcureTrace's subscription; extracted values are verified against your original documents, the review decision is made by a deterministic comparison engine, and your documents are never used to train models.
- Every extraction correction, review decision, run, and deletion is recorded in an append only audit log.
- Deleting a review removes the documents, runs, and review data from the application immediately, leaving an id-only deletion record; short-lived infrastructure backups expire on the provider's standard schedule.
- Accounts use hashed credentials, verified email addresses, expiring sessions, and role based access; an account sees only its own organization's reviews.
Canadian data residency options are available for organizations with specific data-location requirements — ProcureTrace's processing routing is configurable per deployment. Ask us about your requirements.
ProcureTrace holds no compliance certifications at this stage. Upload documents you are authorized to share, redacted where your policies require, and contact admin@procuretrace.com with security questions.