Get Legible

Data security

Your customers can’t proofread our work.
We built for that.

Proofreading a large-print document against its source isn’t an option for someone with a visual impairment. A silently corrupted figure on a bank statement harms the person least able to catch it. So we treat document integrity not as a quality metric but as a safety property — and it sets the one rule everything else answers to:

Never trade correctness for delivery.

Verified, or not delivered

Every document passes through deterministic fidelity gates — exact, rule-based checks that every date, figure, and heading in the large-print output matches the source. Not spot checks. Not AI judgement. Deterministic comparison, every document, every time.

If a gate fails, the document is not delivered. There is no degraded output, no “best effort” mode, no override. The job stops, and the failure is investigated. A wrong document never reaches a reader.

We keep almost nothing

  • Source documents exist in our systems only for processing. Our retention policy purges inputs on completion and holds large-print output only for a short collection window — retention measured in hours and days, not archives.
  • Our audit trail contains no document content. We log counts, timestamps, and cryptographic fingerprints (SHA-256) — never names, balances, account numbers, or any value from any document. If our logs were breached tomorrow, there would be no customer data in them to lose.

This is deliberate. The strongest protection for data is not holding it.

Where your data goes — and where it doesn’t

  • Document extraction runs in the EU, exclusively. Our extraction provider is hard-configured to EU-region processing; documents are never routed to US infrastructure for this stage.
  • Every network leg is encrypted in transit — including internal database and storage connections, with certificate verification enforced in code. TLS is required, not merely available.
  • Payment collection is Stripe-hosted end to end. Card numbers never reach our code, our servers, or our logs — by architecture, not by policy.
  • A full sub-processor list is available to clients, with the role, data scope, and region of every provider we use.

Instructions come only from you

Our pipeline treats text inside an uploaded document as data, never as instructions — even when it is shaped like one. Deterministic gates verify every output against its source before anything is delivered.

Built to be audited

Every job leaves an append-only, hash-anchored audit trail: what came in (by fingerprint, not content), what each stage did, what the gates found, and what went out. It is designed to be shown to a client’s security team, not just kept for ours.

Questions we welcome

If your security or compliance team wants detail — data-flow documentation, our sub-processor list, retention schedules — ask. The documentation exists because we use it.

admin@getlegible.co.uk