Legal

Security at ProcessGround

Effective and last updated: September 21, 2026

This page summarizes the controls and limitations that apply to the current public service. It is not a certification, audit report, or contractual security addendum.

Section 1

Security scope

ProcessGround is currently designed for US self-service customers processing ordinary, non-regulated business documents. It is not approved for PHI, complete payment-card data, government identifiers, credentials, classified information, children's data, or other regulated or high-consequence content.

Section 2

Data handling

Uploaded source files and generated files are processed in memory and are not intentionally persisted in the application database. OpenAI receives relevant document content for request-time analysis. An encrypted, per-account normalized analysis may be retained for up to 30 days to support reproducible reruns.

Operational, security, authentication, billing, and vendor records are retained as described in the Privacy Policy.

Section 3

Current controls

  • Managed passwordless authentication through Clerk and protected server routes.
  • TLS for application and database traffic, encrypted production secrets, and AES-256-GCM encryption for canonical analyses.
  • Stripe-signed billing webhooks, account-bound entitlements, idempotent usage metering, and period-end cancellation.
  • File type, size, complexity, active-content, archive, and export validation.
  • Rate limits, redacted Sentry monitoring, dependency review, retention automation, and database recovery procedures.
  • Source-linked AI output with deterministic graph validation and bounded repair.

Section 4

Product limitations

Generated diagrams are AI-assisted drafts and require human review. Automated checks do not certify accuracy, completeness, audit assurance, control effectiveness, regulatory compliance, or fitness for a high-consequence use.

Section 5

Incident response

We investigate suspected security incidents, contain affected systems, assess legal notification duties, preserve required evidence, and notify affected parties when required by law. Service availability and incident communications may depend on our infrastructure providers.

Section 6

Report a vulnerability

Email kevin@processground.com with a clear description and reproduction steps. Do not access, alter, download, or disclose another person's data; disrupt the service; use automated destructive testing; or publicly disclose an unresolved issue. We will acknowledge good-faith reports as promptly as practicable.