Short version: documents are encrypted in transit and at rest, access is restricted to the processing pipeline and a small number of authorised staff, content is never used to train AI models, and everything is deleted 90 days after upload. The security page has the full detail.
In transit
Everything between your browser and Valify travels over TLS 1.2 or higher. The same applies to every connection onward to our infrastructure providers.
At rest
Uploaded files are held in Supabase Storage, encrypted at rest, in a private bucket that is not publicly addressable. Database rows are protected by row-level security, so a request can only ever return the rows belonging to the authenticated account — the isolation is enforced at the database, not by application code that might forget.
AI processing
Document content is routed through OpenRouter to the AI model — currently Anthropic's Claude — strictly to generate your report. It is not used to train models, and it is not retained by us beyond the 90-day window that applies to everything else.
Access
Access is limited to the automated processing pipeline and a small number of authorised support staff who need it to investigate a problem. There is no administrative interface that browses customer documents for its own sake.
Sharing a report
A shared report link is its own authorisation: anyone with the link can read that report. Send it to the people who need it, not to a group inbox or a public channel, and be aware that a forwarded link keeps working. Shared report pages are excluded from search engines for the same reason.
Deletion
Documents and extracted text are permanently deleted 90 days after upload, automatically. You can delete a document sooner from your document list, and deleting your account removes everything at once.
What we ask of you
- Use a strong, unique password — see how to change my password.
- Do not share accounts between people. Each person should have their own.
- Treat shared report links as confidential.
- Include only the personal data your documents actually need.
For your own security review
Procurement teams normally want the security page, the data processing information and the privacy policy. If you need something those do not cover — a supplier questionnaire, a specific contractual term — contact us and we will answer it properly rather than pointing at a badge. If the review is part of a wider due-diligence exercise, what triggers an HSE investigation is a useful reminder of which records you will need to produce quickly, and where a review tool fits among them.
Was this helpful?
Still need help?
If this did not answer your question, email support@valify.co.uk and we will get back to you as quickly as we can. Tell us what you were trying to do and what happened — it saves a round trip.
Contact Support