Security & Trust

    Built for the security and compliance expectations of banks, credit unions, and private lenders.

    1. Data Protection

    EntityScan AI applies enterprise-grade controls to every customer's data, including EntityScan Assistant conversations and documents created through the Assistant.

    • Encryption in transit using TLS 1.2 or higher.
    • Encryption at rest using AES-256.
    • Logical isolation between customer environments through application-level and cloud-level controls.
    • Access limited to authorized EntityScan personnel and the customer's authorized users, for authorized purposes only.
    • Customer data is never sold or shared with third parties for marketing or commercial purposes.

    2. AI Model Processing

    EntityScan AI uses enterprise-grade AI models from third-party providers, accessed via secure encrypted APIs under enterprise data-protection terms. This includes the EntityScan Assistant as well as report generation.

    Customer data is never routed through consumer AI chat products such as ChatGPT or Claude.ai.

    A detailed list of AI providers and applicable Data Processing Addendum terms is available under NDA upon request as part of vendor due diligence.

    3. No Model Training

    Customer Data is not used to train, fine-tune, or improve public, shared, or third-party foundation models. Customer documents, EntityScan reports, EntityScan Assistant conversations, and documents created through the Assistant are processed solely to deliver the service to that customer.

    4. Cloud Infrastructure

    EntityScan AI is built on Microsoft cloud infrastructure.

    • Hosted on Microsoft Azure.
    • Customer data stored in Microsoft Dataverse.
    • Application runs on multiple application servers hosted in at least two US-based Azure datacenter regions.

    5. SOC 2 Type 2

    EntityScan AI is currently undergoing a SOC 2 Type 2 examination covering the Security trust services criterion. The detailed status of the examination and the final report (when issued) are available under NDA upon request as part of vendor due diligence.

    6. Data Retention and Deletion

    Borrower entity document PDFs are retained for 180 days by default, and reports for 360 days. The Terms of Service establish a minimum retention period of 90 days. Retention is subject to contractual retention obligations and legal-hold requirements. Customers can request deletion of their data subject to those terms.

    Questions?

    For questions about security, compliance, or vendor due diligence, please contact us through our contact form.