Built for deal confidentiality.
Blank processes confidential financial documents, so we built the service around a simple principle: data that no longer exists can no longer be compromised.
Our commitments
No document retention
Blank holds the minimum amount of information and disposes of it permanently at the earliest opportunity. Source documents are erased as soon as processing begins*. How long the deliverable remains available is entirely under your control. No file content or file names ever reach our database.
No model training
Your documents never train a model. We commit to this contractually, and we hold every one of our subprocessors to the same commitment, model providers included.
Processing in the European Union
For European customers, AI inference and document storage can take place entirely in the European Union, on an opt-in basis. Data flows are set out, vendor by vendor, in our privacy policy.
* Contractual commitment: no later than 15 minutes after processing completes. Full retention details in our privacy policy.
Technical and organisational measures
Data protection
Encryption
Data is encrypted in transit (HTTPS, with HSTS across all our domains) and at rest (object storage and database).
Data minimisation
Your file names are never recorded and no content passes through our logs; operational metadata is purged after 365 days, in line with the GDPR and CNIL guidance.
Processing isolation
Your documents are processed in a dedicated service that is never exposed to the internet. Its outbound traffic is restricted to a closed list of known destinations: any other egress is blocked and raises an alert.
No tracking
No behavioural analytics and no advertising cookies. Technical monitoring is limited to errors, hosted in the European Union, and collects no personal data.
Access and segregation
Per-user segregation
Each user works in a sealed space, with no visibility between accounts, even within your own firm. Automated tests verify this on every deployment.
SSO-only sign-in
Sign-in goes exclusively through your identity provider (Google or Microsoft). No password exists at Blank, for any account: password theft and reuse are ineffective by construction, and your own MFA and device policies apply automatically.
Least privilege
Access to our systems follows least privilege: multi-factor authentication on every administrative account, keys scoped to the strict minimum, and quarterly access reviews whose findings we put on record.
Operational vigilance
Vulnerability management
Our integration pipeline blocks vulnerable dependencies and applies patches automatically; every commit is scanned for leaked secrets. The API lives behind a web application firewall with DDoS mitigation.
Incident response
Probes watch processing continuously: an outbound-traffic anomaly or a silent degradation raises an alert. We follow a documented response plan and keep an incident register. Should a breach occur, we are contractually bound to notify you without undue delay, within 72 hours at the latest.
What you can verify
- Subprocessor list
Who processes what, where, and under which transfer safeguards.
- Data Processing Agreement
Our DPA, available in full ahead of any commitment.
- Privacy policy
Data flows, vendor by vendor, and retention periods.
- CAIQ v4.0.3
Full CSA self-assessment provided on request.
- Compliance evidence
Collected monthly, timestamped and cryptographically sealed. Provided on request.
FAQ
Do you use our documents to train models?
No. This commitment is contractual and binds each of our subprocessors, AI model providers included.
Where are our documents processed and stored?
For European customers, AI inference and document storage can take place entirely in the European Union, on an opt-in basis. Data flows are set out, vendor by vendor, in our privacy policy and in our public subprocessor list.
What remains of our documents after processing?
Nothing. Sources are erased the moment processing takes over; contractually, no later than 15 minutes after processing completes. The deliverable disappears within 48 hours, or sooner if you modify the retention period or delete it yourself. Our database retains no file content or file names. At our OCR provider, Zero Data Retention is enabled on our account: nothing is kept there beyond the processing of the request.
Can two colleagues working on separate deals see each other's documents?
No. Segregation operates at user granularity: there is no shared workspace and no cross-account visibility, including within the same firm. Your information barriers hold by design.
Are you SOC 2 or ISO 27001 certified?
Not yet. Our controls are aligned with SOC 2 criteria and continuously documented. Our full CSA CAIQ self-assessment is provided on request.
How can we run a security review of Blank?
The public materials require nothing from us: subprocessor list, full DPA, security.txt. On request, we provide the complete CAIQ questionnaire and our sealed compliance evidence.