Enterprise-Grade Security From Day One

We built Gemina with security at its core. Your sensitive documents are protected by industry-leading standards and regulatory compliance.

GDPR Compliant

Full compliance with EU data protection regulations. We support data subject access requests, right to erasure, data portability, and maintain transparent data practices.

CCPA Compliant

California Consumer Privacy Act compliance ensures your rights to know, delete, and opt-out. We never sell personal information.

Secure by Design

Security is built into every layer of our architecture, not bolted on as an afterthought. From code to infrastructure, we follow security-first principles.

Where Your Data Lives

You choose the region when you set up your account. Documents are processed and stored there, and nowhere else.

AreaLocationNotes
North AmericaUnited StatesSingle region
EuropeFrankfurt and BerlinDual-region — data is replicated across both
AsiaAsiaSingle region
Middle EastIsraelSingle region

You set the retention period

Every document carries an expiry date. Expired documents are purged automatically, and you can delete anything by API at any time.

Your documents never train a model

Customer data and model development are kept strictly separate.

Processing stays in your region

Storage and AI processing both happen in the region you chose — not just the storage.

Defense in Depth

Multiple layers of security protect your data at every stage - from transmission to storage to processing.

Encryption at Rest

All stored data is encrypted using AES-256, the same standard used by financial institutions. Encryption keys are managed by the cloud platform.

Encryption in Transit

All connections are protected with TLS 1.2 or higher. We enforce HTTPS and regularly test our implementation against industry standards.

Secure Infrastructure

Hosted on enterprise-grade cloud infrastructure with automated security patching, network isolation, and 24/7 threat monitoring.

Access Controls

API key management and IP allowlisting. You control exactly who can access your data and from where.

Your Data, Your Rules

Complete control over how your data is stored, processed, and retained. No surprises, no hidden uses.

No Training on Your Data

Your documents are never used to train AI models. We maintain strict separation between customer data and model development.

Data Residency Options

North America, Europe, Asia or the Middle East — named areas, not a vague promise. The table above says where each one puts your data.

Configurable Retention

Set your retention period and data is automatically purged when it expires. Every document has a built-in expiry date - nothing is kept longer than you specify.

Instant Deletion

Delete any document instantly via API or admin console. No waiting, no support tickets - full control to remove data whenever you need.

Complete Visibility Into Your Data

Our admin console provides real-time insights into how your data is being processed and accessed.

Admin Console

Everything controlled from one dashboard. Set retention policies, configure data residency, manage users, and view all extractions in real-time. Full transparency and control.

Real-Time Visibility

View all extractions as they happen. Track processing status, see results instantly, and access detailed reports. Complete visibility into your document processing pipeline.

Penetration Test Completed

AppSec Labs completed an independent compliance penetration test of Gemina’s staging API and console.

The final report, dated September 3, 2026, confirms both findings were fixed and independently verified. There are no outstanding findings in the assessed scope.

About AppSec Labs

Application security specialists since 2010, testing web applications, APIs and mobile apps.

appsec-labs.com

Testing reflects the assessed environment and scope at the time of the engagement.

Who Else Touches Your Data

All document processing, storage, and AI inference happen inside Google Cloud.

Sub-processorWhat it doesScope
Google CloudHosting, storage, and all AI processing — documents are processed and stored exclusively hereRegions per your data-residency setting
CloudflareServes the website and console; traffic passes through its network in transit (TLS)Network and delivery only
PaddleBilling and paymentsAccount and payment data only — never documents
SentryError monitoringTechnical event data — document content and personal data are excluded
Google AnalyticsWebsite usage analyticsSite visitors only, governed by your cookie consent

Last reviewed August 2026.

Questions About Security?

Our security team is here to help. Get answers to your security and compliance questions.