Security & trust

Your clients' documents, handled properly.

Your clients trust you with their most sensitive paperwork — income statements, identity documents, financial records. We treat that trust as seriously as you do. Every file is encrypted in transit and at rest, stored in the EU (Ireland), and reachable only by the people you authorise. You can export or permanently delete your data at any time.

Encrypted in transit & at rest
Hosted in the EU (Ireland)
Access you control
Delete your data anytime

Data encryption and handling

Encryption. All data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256.

Where your data is stored. The application and your uploaded documents are hosted on Heroku (a Salesforce company), with file storage on Amazon Web Services (AWS) — both in the EU (Ireland) region. Your documents do not leave the EU in the ordinary course of using ClientCollect. Two supporting services operate outside the EU — our AI provider and our payment processor — under standard contractual safeguards; see the sub-processor list.

Document lifecycle. Your documents remain available while your account is active. You can delete an individual request, a client, or your entire account at any time. When you delete data it is removed from the live system immediately and purged from encrypted backups within our backup retention window (within 30 days). "Deleted" means gone — we keep no shadow copies.

Access controls

Who at ClientCollect can access your data. We operate on least privilege. Our team does not access the contents of your clients' documents in the ordinary course of business. Access happens only where you ask us to help with a support issue and grant it, or where strictly necessary to operate, secure or repair the service — and such access is limited and logged.

Your controls. Within your firm, access is role-based: administrators manage the account and team; members work on the requests assigned to them. On the client side, each client reaches their documents through a unique secure link and confirms their identity with a one-time code sent to their email — there is no shared password to leak, and links are tied to the individual you invited.

Authentication. Your team signs in without passwords: we send a one-time code to your email each time, so there is nothing to phish, reuse or breach. Single sign-on (SSO / SAML) for larger firms is on our roadmap.

Compliance and legal

GDPR and our DPA. For the documents you collect from your clients, you are the data controller and ClientCollect is your data processor. Our Data Processing Agreement is published and self-serve — you don't need to request it. It sets out our processor obligations, how we assist with data-subject requests, and our security commitments.

Sub-processors. We publish a current, dated list of every third party that processes customer data in Annex 3 of our DPA — hosting, storage, email, payments and AI. In particular, when you use our AI assistant (Colette), the content you send is processed by our AI provider (Anthropic) solely to generate your response and is never used to train AI models.

Certifications. In the interest of honesty: we do not yet hold a SOC 2 or ISO 27001 certification. We inherit strong physical, network and infrastructure security from our providers — Heroku/Salesforce and AWS maintain SOC 2, ISO 27001 and other independent certifications for the environments we run on. We're glad to share our current security documentation and complete a vendor security questionnaire — email security@clientcollect.com.

Operational security

Backups and recovery. Your data is backed up automatically, with encrypted backups retained on a rolling basis so we can recover from a failure.

Infrastructure. We build on Heroku/Salesforce and AWS and inherit their certified physical and network security — data-centre access controls, network protection and more.

People and devices. Everyone with access to production systems follows least-privilege access and secure-device practices, and access is removed promptly when it is no longer needed.

Monitoring and audit trail. Every request keeps a timestamped audit trail — who requested, uploaded, viewed and accepted each document — which you can see in the app. On our side, we monitor and log access to the systems that run the service.

Vulnerability disclosure and incident response

Responsible disclosure. If you believe you have found a security issue, please email security@clientcollect.com. We investigate every good-faith report and will not pursue legal action against researchers who act responsibly and avoid privacy violations or service disruption. Our [security.txt](/.well-known/security.txt) lists the same contact.

Incident response. If a security incident affects your data, we will notify affected customers without undue delay, with the information you need to meet your own obligations. Where a personal data breach is reportable, we support notification to the relevant supervisory authority within the 72 hours required by the GDPR.

Frequently asked questions

Can my clients' data be seen by other firms?

No. Every firm's data is segregated by account. No other customer — and no unauthorised person — can access your clients' documents.

Do you train AI on my documents?

No. Content you send to our AI assistant is used only to generate your response. It is not used to train AI models, by us or by our AI provider.

Where is my data stored?

In the EU (Ireland) — both the application and your uploaded documents. Two supporting services (AI and payments) operate in the US under standard contractual clauses; see the sub-processor list.

Can I get a Data Processing Agreement?

Yes — it is published and self-serve at /dpa. No need to request it.

How do I delete everything if I stop using ClientCollect?

Delete your account from settings, or ask us. We remove your data from the live system immediately and purge it from backups within our backup retention window.

Need our full security documentation?

We're happy to share our security overview and complete your vendor questionnaire. Anyone evaluating ClientCollect can reach our security team directly.