Trust center / Technical controls

Know the boundary before a document crosses it

DocParse is a Cloudflare-hosted parsing service with tenant-scoped access, server-owned routing, explicit provider and host policy, durable usage accounting, and deliberate purge. This page documents implemented technical controls; it is not a certification or legal compliance claim.

01

Access

Tenant API keys are stored as SHA-256 hashes, named, scoped, revocable, and separated from the global administrative credential. Portal sessions use HttpOnly SameSite cookies, same-origin checks, and CSRF tokens.

02

Isolation

Jobs, usage, API keys, portal membership, and artifact paths are tenant scoped. Admission applies tenant monthly jobs, bytes, and concurrency limits before source and job side effects.

03

Egress

Tenant callers fail closed for source URL imports, webhook destinations, and external OCR unless corresponding host or provider policy is enabled. Redirects and special network destinations are rejected.

04

Cost

Trial parsing is deterministic. Model and provider attempts reserve a D1 usage row before inference and respect daily caps. Missing durable accounting blocks spend rather than allowing an unrecorded call.

05

Retention

Job status and deletion are separate. Authorized purge tombstones the job, removes product-owned sources, and deletes shared content-addressed artifacts only when no retained job still references them.

06

Analytics

First-party product analytics stores normalized attribution and event metadata without IP addresses, document text, secrets, or full referrer URLs. Internal and automated traffic are marked for exclusion.

Review

What customers still need to decide

DocParse controls do not determine whether a workload is legally or organizationally appropriate. Customers remain responsible for authorization to process sources, data classification, required agreements, permitted regions and providers, retention periods, user notices, and downstream access control.

For a production assessment, review representative source formats, tenant policy, required external processing, deletion expectations, incident contacts, and the exact deployment configuration. Start with non-sensitive evaluation files.

From answer to evidence

Test the parser on the documents your product actually receives.

Create a free workspace, parse up to 20 text-based documents, inspect Markdown and DocIR, then use the API when the output meets your bar.

Parse a representative document 20 documents · 200 MB · deterministic trial · no payment card