Security & data handling

Stewardship of the record.

We hold public and patient documents the way their custodians do: privately, minimally, and accountably. Here is exactly how your files move through our process — and what happens to them afterward.

The lifecycle of your document

  1. Received & encrypted

    Your file is encrypted in transit (TLS) and at rest. It is stored only as long as needed to quote and complete the work.

  2. Access limited to the work

    Only the specialist assigned to your document — and the reviewer who verifies it — can access it. We do not share, sell, or repurpose your files or their contents.

  3. Verified & delivered

    On completion, you receive the accessible document and its conformance report. We retain the validation record so you have durable evidence of conformance.

  4. Declined means deleted

    If you decline the quote, or once a job's retention window closes, your source file is permanently deleted — and the deletion is recorded.

ENCRYPTION

In transit & at rest

TLS in transit and encryption at rest for every file, throughout the engagement.

ACCESS

Least privilege

Access is limited to the specialist and reviewer working your document. No broader access, no resale.

RETENTION

Minimal & on the record

Declined files are permanently deleted with an audit record; only the validation record is retained.

PAYMENTS

Handled by Stripe

Card payments are processed by Stripe, a PCI DSS Level 1 provider. Your card details go directly to Stripe over an encrypted connection — we never see or store your card number or security code.

Payment security

All online payments are processed by Stripe, a certified PCI DSS Level 1 service provider — the highest level of payment-security certification. Card information is transmitted directly to Stripe over an encrypted (TLS) connection and is never stored on our servers; ClearAccess Documents does not have access to your full card number, expiry, or CVC. All charges are made in U.S. dollars (USD). For details on how payment data is handled, see our privacy policy and refund & cancellation policy.

For healthcare organizations

We understand that patient documents carry additional obligations. We limit the data we hold to what the work requires, restrict access, and make deletion verifiable. A Business Associate Agreement is available on request before you send any protected health information.

For government buyers

Public records deserve the same care. Our handling supports your records-retention and transparency obligations: you keep the conformance report as evidence, and we keep a record of what we deleted and when.

What we don't do. We don't make files public, we don't train models on your documents, and we don't retain source files longer than the work requires. If a security question isn't answered here, ask us — we'll answer plainly.

Questions about data handling?

Ask a person, get a plain answer.

Security reviews, BAAs, and vendor questionnaires are welcome. Email us and a specialist will respond within one business day.

Based inColorado Front Range
Email us