Trust Centre- Security Features and Policies
GoCircl is used by law firms on confidential, pre-release offering documents, and we protect your files and data at every stage, from authentication through to processing and deletion. This page explains how, including where AI is used and which third parties are involved.
Below is a brief summary of our security features, policies and processes. Our System Security Overview, SOC 2 report and policies are available on request; please get in touch.
Enterprise clients. This page describes our standard online service. Firms with specific hosting, data-residency, identity or AI requirements are not limited to it: we offer single-tenant private instances and deployments within your own cloud or network. See Enterprise & Deployment.
Document Processing & AI
GoCircl Ai combines our own deterministic document analysis with one narrowly scoped AI-assisted stage:
- Only the pages that require analysis are sent, individually and over TLS, to our AI sub-processor (OpenAI, under its commercial API terms), solely to identify which figures should be circled.
- The model returns text references only. It never returns an annotated file, and it cannot draw on or alter your document.
- Every annotation is then drawn and validated deterministically on GoCircl’s own servers.
Your documents are never used to train any model. We have executed OpenAI’s Data Processing Agreement. Under OpenAI’s API terms, inputs may be retained for up to 30 days solely for abuse monitoring, then deleted; we have requested zero-data-retention treatment, which removes that retention once enabled. Our use of AI is governed by our Ai Acceptable Use and Governance Policy, aligned to the NIST AI Risk Management Framework. For background on what GoCircl does to a document, see our guide to auditor circle-ups.
File Retention & Deletion
To minimize risk from a potential breach, every PDF you upload, and every annotated file we produce, is automatically purged from our servers after 60 minutes. You can track this countdown in your GoCircl Dashboard. We do not back up client documents, and a shorter retention window is available for enterprise engagements.
Encryption
All communication between your browser and GoCircl is secured using HTTPS with Transport Layer Security (TLS 1.2/1.3), and inter-service traffic travels inside Fly.io’s private WireGuard network. At rest, databases and volumes are encrypted by Fly.io using LUKS disk encryption, and stored files use server-side encryption on Tigris, Fly.io’s object storage service.
Cloud Infrastructure & Compliance
GoCircl holds a SOC 2 Type II report for the Security criterion, issued by an independent AICPA firm with no exceptions noted. A copy is available under NDA.
Our standard service is hosted on Fly.io, which is independently audited to SOC 2 Type II and operates within ISO 27001-certified data centres. Fly.io is our default rather than a requirement: enterprise clients can be deployed as a private instance on Fly.io, AWS or Azure, or within their own tenancy. See Enterprise & Deployment. We maintain business continuity, disaster recovery and incident response plans, tested annually, with a 12-hour recovery objective.
Sub-processors
Client documents and account data are shared only with the sub-processors needed to run the service:
- Fly.io: cloud hosting and infrastructure, including Tigris object storage.
- OpenAI: AI-assisted page analysis, as described above.
- Stripe: subscription and payment processing; GoCircl stores no card data. Read more about Stripe’s security measures.
- ZeptoMail (Zoho): transactional email, such as account verification.
We use Google Analytics to measure website and product usage; it never receives your documents or their contents. This list reflects the standard service. In an enterprise deployment it can be narrowed. For example, Stripe is not used, email can run through your own mail relay, and the AI stage can run under your firm’s own AI account or a model endpoint in your own tenancy.
Access Control
Your documents are reachable only through your own authenticated account: every request is checked against document ownership, and files are never exposed at a public URL. Administrative access is limited to named personnel under confidentiality obligations, for maintenance only, and any support-related access relies on your initiation and consent.
Data Minimization
We collect only your name, email address and country to create an account. For each document we keep minimal metadata (file name, upload time, page count and processing status), while the document itself is purged within 60 minutes. We ask that you do not upload protected health, payment card, biometric or genetic data.
Data Ownership & Residency
Your documents and data remain your exclusive property. In the standard service, all data is processed and stored in the United States. Enterprise clients can choose their region, and where the AI-assisted analysis takes place. See Enterprise & Deployment.
Legal Notice
As a user (whether on a free or paid tier), you acknowledge and agree that you are using the system at your own risk, you will abide by our Acceptable Use terms and that all disclaimers and in particular, the Limitation of Liability section in our Terms of Use and Privacy Policy apply to your use of any system.