← Back to Home

Security Overview

Last Updated: January 2025

Purpose of This Document

This Security Overview describes our security approach but does not constitute a guarantee, warranty, or service-level commitment. Actual practices may evolve.

Security Philosophy

ArchiveView follows commercially reasonable security practices and industry standards appropriate for a cloud document-management platform.

Encryption

Data at Rest

AES-256 server-side encryption in AWS S3 and databases.

Data in Transit

TLS 1.2+/1.3 enforced.

Backups

Encrypted, versioned, geographically redundant.

Access Controls

MFA supported, strong password enforcement, session controls, RBAC permissions, least-privilege principles, organization isolation, and audit logging.

Infrastructure Security

Hosted on AWS using VPC isolation, private subnets, security groups, hardened serverless architecture, and automated dependency scanning.

Application Security

Sanitized input handling, API throttling, code reviews, static analysis, vulnerability scanning, and regular security testing. We engage third-party assessments periodically.

Monitoring & Logging

User activity logging, anomaly detection, alerting, attempted intrusion monitoring, and periodic log review.

Incident Response

We maintain incident response procedures designed to detect, contain, and remediate security events. We notify customers of incidents affecting their data in a commercially reasonable timeframe.

Customer Responsibilities

Customers must enable MFA, secure accounts, manage permissions, classify sensitive documents appropriately, and avoid uploading prohibited data types.

Compliance & Standards

We follow privacy and security principles aligned with frameworks such as GDPR, CCPA, and SOC2 best practices but do not claim formal certification unless explicitly stated.

Third-Party Providers

AWS, Anthropic Claude, Amazon Textract, email & payment vendors may process data. We vet vendors and maintain data processing agreements where required.

AI Considerations

Documents or extracted content sent to AI/OCR models are used only to provide the Service. AI output may be inaccurate and must be verified by the customer.

Physical Security

AWS provides physical data-center protection including access controls, surveillance, and environmental safeguards.

Changes

This overview may be updated periodically.

Contact