Security
Security you can take to diligence.
Encryption in transit and at rest. Your data is never used to train models. Here is exactly what we do, stated only as far as we can prove it.
SOC 2 Type 2, Security criteria.
GoodStream completed a SOC 2 Type 2 examination covering the Security Trust Services Criteria for the period March 25 to June 25, 2026. Ezzy & Associates LLC, an independent, Illinois-licensed CPA firm, tested the design and operating effectiveness of our controls and issued an unqualified opinion. The full report is available under NDA.
We do not use customer documents or extracted data to train or fine-tune AI models, ours or any provider's. We do learn from how documents are processed to improve our extraction prompts and review workflows; that work does not create model training data. This is stated in the system description of our SOC 2 report and in our customer agreements.
SOC 2 is an ongoing program for us. We will publish details of our next examination period here when the next report is issued.
Opens our trust center, where you can request the report. Requests are reviewed and the report is delivered under NDA.
Prefer email? Write to security@goodstream.com.
- Report type
- SOC 2 Type 2
- Criteria
- Security (TSP 100)
- Period
- March 25 to June 25, 2026
- Report date
- September 1, 2026
- Opinion
- Unqualified
- Auditor
- Ezzy & Associates LLC, Illinois-licensed CPA firm
- Subservice organizations (carve-out)
- Cloudflare, Google Cloud Platform, Neon
Encryption everywhere
- TLS 1.2 or higher in transit
- AES-256 at rest
- Secrets managed in a dedicated secrets manager, never in source code
Access control
- Single sign-on available for customer organizations
- Multi-factor authentication supported for every user account and enforced for all GoodStream production access
- Granular role-based permissions
Audit logging
- Access logging on every API call
Tenant isolation
- Row-level security enforcing organization isolation on every query
Your data stays yours
- No model training on customer data
- Isolated processing
- Explainable outputs with confidence scores and source attribution
Compliance posture
- SOC 2 Type 2 (Security), unqualified opinion
- Working toward GDPR alignment
- Working toward CCPA alignment
LLMs will never train on your data.
No AI provider trains on your data - our enterprise agreements with our model providers prohibit it. Processing happens in isolated environments and providers retain nothing beyond the processing session.
Human oversight, with boundaries.
Critical decisions require human approval. Confidence thresholds are configurable, and low-confidence extractions route to our review team automatically. Our reviewers work under strict confidentiality agreements, their document access is scoped to the review at hand, and every access is logged.
Who can see your documents.
Document review is performed by GoodStream personnel under written confidentiality agreements. Access is scoped to the documents under review and every access is logged. Personnel hired since the start of our SOC 2 program undergo third-party background screening before receiving document access.
AI providers.
Documents are processed through Anthropic, OpenAI and Google Vertex AI, routed through Vercel AI Gateway. Under our agreements with these providers, none of them use our data to train their models. Providers retain nothing beyond the processing session.
Testing and response.
Independent penetration testing is performed annually and on an as-needed basis for new releases. The most recent test was completed in March 2026 by Casco; an executive summary is available under NDA.
We run a documented incident response process with executive escalation, and we notify affected customers under the terms of our customer agreements. Production database backups are taken daily and retained for 30 days.
For your vendor due diligence questionnaire.
- Report type:
- SOC 2 Type 2
- Criteria:
- Security
- Period:
- March 25 to June 25, 2026
- Report date:
- September 1, 2026
- Opinion:
- Unqualified
- Auditor:
- Ezzy & Associates LLC, Illinois-licensed CPA firm
- Subservice organizations:
- Cloudflare, Google Cloud Platform, Neon (carve-out method)
Complementary user entity controls:
- 1) Users maintain the confidentiality of their credentials and report suspected unauthorized access promptly.
- 2) Users provision and deprovision accounts in their own systems in a timely manner.
- 3) Users review access rights to their GoodStream accounts periodically.
- 4) Users classify and escalate incidents under their own incident response procedures.
Copy this block into your DDQ. Request the full report for control-level detail.
Need a Data Processing Agreement or a security questionnaire completed? We do this every week.
Or email security@goodstream.com to request our security pack.
Security questions.
How is my data encrypted?
All data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Encryption keys are managed through our infrastructure providers' key management services.
Is my data used to train AI models?
No. Your documents are never used to train or fine-tune any model, ours or a provider's. We do use what we learn from processing documents to improve our extraction prompts and review workflows; that work is not model training and nothing is shared between clients.
What access controls does GoodStream provide?
Role-based access controls, single sign-on and multi-factor authentication via Clerk, and granular permissions, with audit logging of access and changes.
What is the difference between a SOC 2 Type 1 and Type 2 report?
A Type 1 report covers whether controls were suitably designed as of a single date. A Type 2 report covers whether they were suitably designed and operated effectively over a period, tested by an independent CPA firm. Ours is Type 2, covering March 25 to June 25, 2026.
Security contact: security@goodstream.com
Last reviewed: September 10, 2026