Where documents are stored
Uploaded documents are stored in a private Supabase Storage bucket with encryption at rest by default. Access is restricted to the systems and processes required to run your scan — there is no direct read/write access from the browser, only short-lived signed URLs issued by our backend.
Encryption standards
Documents are encrypted in transit using TLS 1.2 or higher between your browser and our servers, and encrypted at rest in storage.
How documents are processed
Uploaded documents are stored in Supabase Storage and analysed by routing the extracted content through OpenRouter to a large language model (currently Anthropic's Claude Sonnet). The model processes the content solely to return an analysis to Valify, does not retain uploaded documents after the analysis has been returned, and does not use your content to train models.
Data retention
Uploaded documents and their reports are retained for 90 days from the date of upload, then permanently deleted from our systems. Account and billing records are retained separately as required for legal and accounting purposes.
Document audit trail
Every review decision made in Valify — acceptance or return for revision — is logged with a timestamp and the identity of the person who made it. They are stored in Supabase with row-level security ensuring only your account can access your own records, and are available to export on request.
A decision record is written once and never rewritten: there is no update or delete path from the browser, so a decision cannot be quietly amended after the fact. Changing your mind means uploading the revised document, which produces a new report and a new decision alongside the original rather than in place of it.
Decision records are kept with the document, and go when it does. They are deleted along with the document and its report 90 days after upload, or sooner if you delete it yourself. We would rather say that plainly than describe the audit trail as permanent: the 90-day promise above applies to the whole record of a document, and an exception carved out of it would make that promise worth less. If you need a decision on file for longer than 90 days, export it before then — email support@valify.co.uk and we will send you the records for your account.
Who can access uploaded documents
Access to uploaded documents is restricted to the automated processing pipeline and a small number of authorised Valify personnel for support and debugging purposes only. Documents are never accessed directly from the browser — every read goes through a short-lived signed URL issued by our backend.
GDPR compliance
Valify is built to be compliant with UK GDPR and the Data Protection Act 2018. You have the right to access, correct, or request erasure of your data at any time — see our Privacy Policy for full detail, including how to make a data request.
Third-party processors
Valify uses the following third-party processors (sub-processors), each bound by its own data processing terms:
- Supabase — authentication, database and document storage
- OpenRouter — routes document content to the AI model used for analysis (currently Anthropic Claude)
- Stripe — payment processing and billing
- Resend — transactional email delivery
- Vercel — website hosting and content delivery
See our Privacy Policy for the full sub-processor list and international transfer safeguards.
Reporting a security concern
If you believe you have found a security issue affecting Valify, email security@valify.co.uk with the details and we will respond as a priority. If you are not sure whether something counts as a security issue, send it there anyway — we would rather read one that turns out to be nothing.
See what Valify finds in your documents.
3 free scans. No card required. No commitment.
Get Started — Redeem Your 3 Free Scans