Last updated: February 2026
All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS). Database connections use TLS encryption. Uploaded PDF files are encrypted at rest using AES-256 in our cloud storage. Database backups are also encrypted at rest.
We implement strict multi-tenant data isolation using PostgreSQL Row-Level Security (RLS). Every database table is protected by RLS policies that ensure users can only access data belonging to their organization.
Our application is deployed on enterprise-grade cloud infrastructure with automatic scaling, redundancy, and geographic distribution.
We take data privacy seriously and design our systems with compliance in mind.
In the event of a security incident, we follow a structured response process: identification, containment, eradication, and recovery. Affected customers will be notified within 72 hours of a confirmed breach, in compliance with applicable regulations. We maintain incident response procedures and conduct periodic tabletop exercises to ensure readiness.
We welcome security researchers to report vulnerabilities responsibly. If you discover a security issue, please contact us at security@poprocessing.com. We commit to acknowledging reports within 48 hours and providing status updates as we investigate. We will not take legal action against researchers who follow responsible disclosure practices.