How Blue-IQ protects your contracts.
A summary of the controls in place today. A detailed overview is available to customers on request.
- Authentication
- Sign-in uses the Secure Remote Password protocol through Amazon Cognito, so passwords never cross the network. Every API request carries a verified token, and MFA can be enforced per tenant.
- Encryption
- All traffic is encrypted in transit. Files, database records and search indices are encrypted at rest.
- Tenant isolation
- Each customer's data is partitioned by tenant. Every request re-checks that the record's tenant matches the caller's verified token.
- AI processing
- Contract text is sent to our model provider for clause classification under an enterprise data-handling agreement. It is not used to train shared models and is not retained by the provider.
- Retention and deletion
- Documents are kept while your account is active. Deleting one removes the original file, all processed artefacts, the search index and the database records.
- Breach notification
- Affected customers are notified without undue delay, and within 72 hours of our becoming aware.
- Report a vulnerability
- Disclose it responsibly to security@blue-iq.ai.