Trust center

Security facts for a clear review.

Understand what Routeser protects, which data and regions each control covers, what your organization must configure, and what evidence is available.

Control summary

Safeguards and customer responsibilities

Encryption TLS

Routeser requires encrypted transport for public and service connections and server-side encryption for regional document storage.

Scope: Public APIs, service connections, and document objects in every enabled AWS region.

Customer action: Use the published HTTPS endpoints and protect account and API credentials.

Evidence: Request transport and storage-control evidence through the security review path below.

Regional document processing REG

Document bytes and extraction job state remain in the AWS home region selected for the job.

Scope: Production document processing in us-west-1. Identity, tenant administration, analytics archives, and model processing have separate locations.

Customer action: Confirm eligible regions and model-processing requirements before sending regulated data.

Evidence: Request the current data-flow and regional-control summary through the security review path below.

Retention 90D

Raw documents expire after 90 days and extraction results expire after 90 days under the production retention policy; derived artifacts have shorter lifecycle policies.

Scope: Regional document objects, extraction results, and temporary processing artifacts.

Customer action: Use extraction deletion when your policy requires removal before scheduled expiry.

Evidence: Request the current retention configuration and lifecycle-control summary through the security review path below.

Deletion DEL

Deletion tombstones job state, removes result and error fields, and removes current access to the raw object. Stored versions are cleared by version-aware deletion or lifecycle expiry.

Scope: The requested extraction and its regional raw document object.

Customer action: Submit deletion for each extraction that must be removed before retention expiry and retain the response for your records.

Evidence: Request the deletion contract and focused verification evidence through the security review path below.

Data minimization MIN

Routeser excludes raw documents and extracted values from application log events and sends document content to model services only when needed for extraction.

Scope: Console, API, regional processing, operational analytics, and model requests.

Customer action: Do not place unnecessary personal data in filenames, schema descriptions, or support requests.

Evidence: Request the logging and model-data-handling summaries through the security review path below.

Access control IAM

Tenant API keys are stored and compared as SHA-256 digests. Enterprise workspaces support SSO, required-SSO and MFA policies, SCIM provisioning, and role-scoped membership.

Scope: Human access to organizations and service-account access to tenant APIs.

Customer action: Apply least privilege, review members and service accounts, revoke unused keys, and configure the sign-in policy your organization requires.

Evidence: Account-specific members, roles, SSO policy, and credentials are visible in the console; request broader control evidence through security review.

Evidence

Available material and request paths

Public download: security.txt publishes the security reporting channel. The subprocessor register and its review date are published below.

Security review: request current questionnaire responses, a data-flow summary, and scoped control evidence at security@routeser.com. Confidential or security-sensitive material is shared only after scope and disclosure review.

Not available: Routeser has no SOC 2 report, ISO 27001 certificate, independent penetration-test report, or related remediation letter.

Who processes data

Subprocessors

Vendors that may process customer data to deliver Routeser. Last reviewed 2026-07-24.

Routeser targets at least 30 calendar days' advance notice before a new subprocessor begins processing customer data or an existing subprocessor materially changes purpose or processing location. This target is not a contractual notice period unless it appears in an executed agreement. Customers should provide a legal or privacy contact for notices and review the applicable agreement for objection rights.

SubprocessorPurposeData categoriesScope
CloudflareGlobal edge, public API entry, account and analytics Workers, D1 identity storage, queues, and transactional auth email (magic link, verification, email-change, invitations).Request metadata, human identity, tenant control-plane state, and auth email recipient addresses and message content. Document bytes are not routed through the edge.Global edge network and transactional email
Amazon Web ServicesRegional serverless compute (Lambda), object storage (S3), job state (DynamoDB), and queues (SQS) for document processing.Uploaded document bytes, rendered pages, extraction job state and results.us-west-1, ap-south-1
OpenRouterModel-access gateway that routes extraction requests to the configured model vendors.Page content required for extraction and the extraction schema.Model routing provider
Google (Gemini)Vision-capable extraction model reached through OpenRouter (primary and one fallback route).Page content required for extraction and the extraction schema.Model vendor via OpenRouter
MiniMaxVision-capable extraction model reached through OpenRouter (fallback route).Page content required for extraction and the extraction schema.Model vendor via OpenRouter
PaddleMerchant of record for subscription billing, checkout, tax handling, and payment processing.Billing contact and payment details entered at checkout. No document content.Billing / payments

Legal and privacy

Legal entity: Routeser has not yet published a verified operating legal entity or registered address. Obtain the contracting party's legal name, address, and jurisdiction before signing or relying on contractual terms.

Data Processing Addendum: a structural draft exists, but it is not counsel-approved, available for signature, or a contractual offer. Send your processing scope and jurisdiction requirements to dpa@routeser.com to confirm current status.

Customer action: do not treat this page as a contract. Confirm the entity, DPA terms, subprocessor notice clause, residency scope, and any required commitments in an executed agreement.

Assurance

Not yet attested

Routeser has no SOC 2 report and no ISO 27001 certificate. No auditor, certification body, assessment period, or certification date has been selected or scheduled.

No independent penetration test has been recorded. Routeser does not represent external testing or certification as underway.

Review status: the subprocessor registry was last reviewed 2026-07-24 and is reviewed at least quarterly and after provider or data-category changes. Other control evidence has no single published review date; request its current scope and review status before relying on it.

Report a suspected vulnerability or request security material at security@routeser.com.

FAQ

Frequently asked questions

What assurance certification does Routeser claim?

None. Routeser has no SOC 2 report or ISO 27001 certificate and is not yet externally attested.

How long are production documents retained?

Raw documents expire after 90 days and extraction results expire after 90 days. Derived processing artifacts have shorter lifecycle policies, and customers can request earlier extraction deletion.

Does regional processing cover every data category?

No. It covers document bytes and extraction job state. Identity, tenant administration, analytics archives, and model processing have separate location boundaries.

Next step

Start a security review

Send the data scope, regions, assurance needs, and evidence your organization must evaluate.

Request review