Skip to content
← Enterprise

Privacy, by design

Security at PerfectPaper

How we keep your research private and secure — from upload to deletion.

This page describes our current security design and readiness programme. It is not a certification, audit report, penetration-test result, or service-level agreement.

Encryption

PerfectPaper is designed to protect manuscripts in transit and at rest using application and provider security controls. Access is scoped by account, organisation, workspace, role, ownership, and explicit grants. Production encryption settings and provider attestations are reviewed as part of our compliance programme.

Never used for training

Your papers are yours. PerfectPaper does not use manuscripts, supporting files, prompts, generated feedback, reasoning content, or tool activity to train generative models. Content is sent only through configured commercial APIs needed to deliver the requested review; provider retention and regional terms are assessed separately.

Input sanitisation

Uploaded text is run through Unicode sanitisation before processing, removing hidden and malformed characters that could otherwise interfere with a review.

Retention and deletion

You can request deletion through the product and our privacy process. We are formalising retention schedules and end-to-end deletion verification across application data, object storage, backups, and service providers; legal holds and required records may delay deletion.

Compliance

We maintain a SOC 2 readiness programme covering security, availability, and confidentiality. PerfectPaper has not yet received a SOC 2 report or ISO 27001 certification. Current readiness documentation and known gaps are available for enterprise diligence.

Governance and assurance

Our control programme includes enterprise risk assessment, system and AI threat modelling, assigned control roles, security training requirements, vendor review, management reporting, and documented exception and remediation targets. Policies are being prepared for executive approval and operating evidence collection.

Questions about security?

We're happy to walk your IT or procurement team through our data handling and compliance roadmap.