Security & Trust
Built for the security and compliance expectations of banks, credit unions, and private lenders.
1. Data Protection
EntityScan AI applies enterprise-grade controls to every customer's data, including EntityScan Assistant conversations and documents created through the Assistant.
- Encryption in transit using TLS 1.2 or higher.
- Encryption at rest using AES-256.
- Logical isolation between customer environments through application-level and cloud-level controls.
- Access limited to authorized EntityScan personnel and the customer's authorized users, for authorized purposes only.
- Customer data is never sold or shared with third parties for marketing or commercial purposes.
2. AI Model Processing
EntityScan AI uses enterprise-grade AI models from third-party providers, accessed via secure encrypted APIs under enterprise data-protection terms. This includes the EntityScan Assistant as well as report generation.
Customer data is never routed through consumer AI chat products such as ChatGPT or Claude.ai.
A detailed list of AI providers and applicable Data Processing Addendum terms is available under NDA upon request as part of vendor due diligence.
3. No Model Training
Customer Data is not used to train, fine-tune, or improve public, shared, or third-party foundation models. Customer documents, EntityScan reports, EntityScan Assistant conversations, and documents created through the Assistant are processed solely to deliver the service to that customer.
4. Cloud Infrastructure
EntityScan AI is built on Microsoft cloud infrastructure.
- Hosted on Microsoft Azure.
- Customer data stored in Microsoft Dataverse.
- Application runs on multiple application servers hosted in at least two US-based Azure datacenter regions.
5. SOC 2 Type 2
EntityScan AI is currently undergoing a SOC 2 Type 2 examination covering the Security trust services criterion. The detailed status of the examination and the final report (when issued) are available under NDA upon request as part of vendor due diligence.
6. Data Retention and Deletion
Borrower entity document PDFs are retained for 180 days by default, and reports for 360 days. The Terms of Service establish a minimum retention period of 90 days. Retention is subject to contractual retention obligations and legal-hold requirements. Customers can request deletion of their data subject to those terms.