SECURITY
How we protect your documents
Your customs documents show who you buy from, what you pay and how much you import. This page sets out where they are stored, who can see them and what we have not built yet — in enough detail for your IT or procurement team to check.
Last reviewed: 18 September 2026
Stays in the EU
Servers in Germany, documents and backups in France, AI reading in EU regions only.
Accounts kept apart
Every request is checked on our servers against the account it asks for.
Encrypted backups, nightly
Encrypted before they leave our server, so the storage provider cannot read them.
No training on your data
The AI model reads your documents to extract the figures. Nothing else.
Where your data lives
We run the application, its database and the sign-in service ourselves, on servers we rent from OVH in Germany.
| What | Where | Provider |
|---|---|---|
| Application, database, sign-in | Germany (Cologne) | OVH — operated by tarify |
| Your documents | France (Paris), stored across three data centres | OVH Object Storage |
| Nightly backups | France, encrypted before upload | OVH Object Storage |
| AI document reading | EU only: Frankfurt, and under load Ireland, Paris, Stockholm, Milan or Spain | Amazon Web Services (Bedrock) |
| Germany | Amazon Web Services (SES), mailbox.org | |
| Payments | EU / USA | Stripe — your card details go to Stripe, never to us |
The complete and binding list of sub-processors is in our privacy policy and in Annex II of the data processing agreement. Privacy policy · Data processing agreement
Encryption
What is encrypted, and how.
Every connection
Traffic between your browser and tarify, and between tarify and its providers, runs over TLS.
Backups
Encrypted on our own server before upload, with a key the storage provider never sees. Even the file names are encrypted.
Your Google or Microsoft connection
If you connect a drive or a mailbox, its access token is stored encrypted (AES-256-GCM) under a key used for nothing else.
Passwords
Stored only as salted hashes. Nobody at tarify can read them.
Opening a document
Each time you open a document, tarify creates a private link that stops working after five minutes.
Who can see your data
The people you invite, and nobody else — checked on our servers for every request, not just hidden in the interface.
Accounts are kept apart
Every request is checked against your account membership. Ask for another company's document and the answer is "not found" — the system does not even confirm that it exists.
Roles for your team
Owner, admin, member and viewer. Every function states which role it needs, and our automated tests fail if a new one does not.
Sign-in tokens our own servers cannot forge
The sign-in service signs tokens with a private key that the application servers do not hold. They can check a token, but cannot create one.
A closed database
The database runs on a private internal network and cannot be reached from the internet.
Our support access is read-only
Only named tarify operators can open a customer account, and only to read — they cannot upload, change, confirm or delete anything. Every access is logged.
AI document reading
A language model reads your documents, so you don't have to type the figures in.
EU regions only, enforced
The model runs on Amazon Bedrock in EU regions. An access policy on our AWS account blocks it in every region outside the EU.
The model's developer never sees your documents
The model is Anthropic's Claude, operated for us by AWS. Anthropic does not receive what you upload.
No training
Your documents and the model's answers are not used to train or improve any model.
You check every figure
Each extracted value is linked to the exact text it came from. If something is missing, tarify stops and asks — it never fills in a zero.
A record of what happened
So you can show your authority how a figure came about.
Processing log
Every time a document is processed, an entry is written to an audit log. Our code only ever adds entries; it has no way to change or remove them.
Corrections are kept, not overwritten
If you correct an extracted value, the correction is stored as its own record — the value before, the value after, and who made the change.
Retention and deletion
Your data is yours to take with you, and it is deleted when you leave.
Export, then deletion
When you close your account you can export your data first. We then delete it within 30 days; backups age out in the normal backup cycle.
Two exceptions the law requires
CBAM records must be kept until the end of the fourth year after the declaration (Regulation (EU) 2023/956). We unlink them from your account and delete them once that period ends. The audit log is kept as a legal record of processing.
How we build and run it
The routines that keep a mistake from reaching your data.
Tested before production
Every change goes through a separate staging environment first — its own database, storage and sign-in service, filled with synthetic data, never a copy of customer data.
A rollback we have practised
Any release can be rolled back to the previous version with one command. We have done it for real, not just written it down.
Backups we have restored
Backups run every night and raise an alarm if they fail. We have restored one into a separate database and compared it table by table.
No secrets in the code
Keys and passwords live in protected configuration on the server, never in source control.
Limits on the public tools
The free calculator and document scanner have daily limits, per visitor and overall, so nobody can run up cost or load through them.
What we don't have yet
Better you hear it from us than find it in a questionnaire.
No ISO 27001 or SOC 2 certificate
tarify is not certified yet. If your procurement requires a particular certificate, tell us — it helps us decide what comes first.
No two-factor sign-in
Today you sign in with a password or with a one-time code sent by email.
No independent penetration test
Our own automated tests cover roles and permissions. An outside firm has not tested tarify yet.
For your IT and procurement team
Every customer gets our data processing agreement under Art. 28 GDPR — accepted at sign-up, or countersigned on request. It lists every sub-processor and our technical and organisational measures. Send us your security questionnaire and we will fill it in.
Data processing agreementPrivacy policy
contact@tarify.ioReport a vulnerability
Found a security problem? Email us the steps to reproduce it. Please do not access other people's data or disrupt the service while testing.
If a breach ever affects your data, we tell you without undue delay, with the information you need for your own notifications.
security@tarify.io