Enterprise launch is blocked until the controls described as active—including full regional content boundaries and transient deletion—have been technically verified.

1. Data minimization and architecture

The validation data path is stateless with respect to file content. Submitted files and result JSON are excluded from application logs, analytics, crash reports, databases, object storage, and backups. Temporary working data is destroyed at request completion, failure, or timeout. Only the content-free metadata listed in the Privacy Policy enters durable systems.

2. Regional processing

Customers choose an available EU or US processing region. Google Cloud compute and temporary resources are pinned to that region. Cloudflare regional services or an architecture that avoids out-of-region TLS termination keeps decrypted XBRL content inside the selected boundary. Region controls are verified before a region is offered.

3. Encryption and secrets

  • External traffic uses current industry-standard TLS; internal service traffic carrying sensitive data is encrypted in transit.
  • Retained account, billing, usage, and security metadata is encrypted at rest using managed infrastructure encryption.
  • API secrets are generated with strong randomness, displayed only when issued, and stored only as non-recoverable hashes or equivalent verifiers.
  • Customers can create, label, rotate, and revoke API keys. Secrets are not included in logs or support output.

4. Identity and access

Access follows least privilege and role separation. Administrative access is limited to authorized personnel, reviewed periodically, protected by strong authentication, and logged. The customer portal supports multi-factor authentication and organization-scoped roles. Customer tenants are logically isolated and authorization is enforced server-side.

5. Secure operations

  • Production changes use version control, review, automated build checks, and controlled deployment.
  • Operating systems, runtimes, and dependencies are monitored and patched according to risk.
  • Security-relevant events are monitored and retained for 90 days without file content or validation results.
  • Personnel with production responsibilities are bound by confidentiality and receive security guidance.
  • Providers are reviewed for their role, contractual safeguards, regional capabilities, and security posture.

6. Vulnerability management

EasyBRL tracks relevant security advisories, scans dependencies and images as part of the delivery process, prioritizes remediation based on exploitability and impact, and may apply emergency changes without ordinary maintenance notice. Report suspected vulnerabilities privately to [email protected] and do not access another customer’s data or disrupt the Service.

7. Availability and recovery

Hosted infrastructure uses health checks, monitored capacity, restart and replacement mechanisms, and documented recovery procedures. Durable metadata is backed up in encrypted form; expired backup copies are removed within 30 days. Submitted files and validation results are never backed up. The public SLA defines availability commitments.

8. Incident response

EasyBRL maintains procedures to identify, contain, investigate, remediate, document, and learn from incidents. Customers are notified without undue delay after confirmation of a personal data breach affecting their Customer Data, with material updates as facts become available. Legal reporting duties are coordinated under the DPA.

9. Secure deletion

Transient working storage is request-scoped and deleted at completion, failure, or timeout. Durable metadata is automatically aged out under the published retention schedule. Deletion from active systems is followed by expiry from encrypted backups within 30 days, unless a documented legal hold applies.

10. Customer responsibilities and assurance

Customers must protect credentials, configure least-privilege access, rotate keys, maintain secure client systems, classify data before submission, and notify EasyBRL of suspected compromise. Self-hosted customers control all runtime security and operations.

EasyBRL does not currently represent that the Services are SOC 2 certified, ISO 27001 certified, independently penetration-tested on a stated cadence, or suitable for a regulated data class unless an order expressly says so. Security questionnaires and reasonable supporting information are available under confidentiality.

Contact

Questions about this document can be sent through the contact form or to [email protected].

Complete purchase

Enter your details and continue to secure payment.

Enterprise XBRL package validation

Choose a service term or contact us about procurement.

Contact PenguinXBRL

Tell us who to contact and what you need.

Cookie settings

Choose whether optional advertising and analytics may run in this browser.

Necessary

Preference, security, checkout, and requested session functions.

Always on