Security & Compliance

Last updated: 2026-09-10

Our approach to trust

Dynamite Docs is built for documents you would not want on the open internet, such as invoices, bank statements, credit-card statements, W-9s, contracts, and audit evidence. That shapes how we build: encryption on by default, no training on your documents, and control over which AI providers handle your data. We publish the controls we actually operate rather than claiming certifications we do not yet hold. The private document AI guide shows how browser-only files, cloud storage, provider routing, BYOK, and local Ollama fit together.

Encryption

  • All traffic is encrypted in transit (TLS).
  • Stored documents and tables are encrypted at rest.
  • Provider (BYOK) API keys are encrypted with AES-256-GCM before storage and are never sent to the browser.

No training on your data

Your documents are processed for the extraction you request and are never used to train foundation models. Free files stay in browser storage. Hobby, Pro, and Ultra files may remain in encrypted cloud storage until you delete them, subject to the account storage allowance and retention policy. Provider trust metadata identifies backends that may train on submitted content so routing policies can exclude them.

Access control

Every document is scoped to its owner. Anonymous viewers can only read a creator's data with that creator's private token, and file download URLs are signed and time-limited. Provider keys live server-side only.

Data residency & sovereignty

You choose the model and provider. Pro and Ultra include an EU-only data-residency policy. Hobby, Pro, and Ultra can send document bytes to the signed, loopback-only Ollama companion for local model inference; account and workspace features remain hosted. See the Privacy Policy for details.

Retention & deletion

You can delete a document, folder, or extraction at any time and it is removed from storage immediately. Anonymous processing data is swept after 7 days. On request, your data is deleted within 30 days except where law requires retention. See the data retention policy.

Subprocessors

We rely on a small set of providers for infrastructure and AI inference. Every subprocessor is contractually bound to protect your data to the standard required by our DPA.

Compliance status

Dynamite Docs is designed around the EU and UK GDPR and comparable data-protection laws, and provides a Data Processing Agreement and data-subject rights as described in the Privacy Policy. Any future certifications will be listed here only once they are actually issued.

Report a vulnerability

We take security reports seriously and will respond promptly. Please email info@dynamitedocs.com with the subject line “Security” and include as much detail as you safely can. Never include live production data in a test.

Open the Dynamite Docs app or return to the homepage.

Loading Dynamite Docs… This page is taking longer than expected. Reload page.