Security & scope

We protect files in motion, not certify your company

CleanRecordsHQ encrypts data at rest and in transit, maintains subprocessors under DPAs, and never sells your uploads. It does not issue HIPAA BAAs, SOC 2 attestations, or legal opinions—your counsel still owns regulatory posture.

Plain-language boundary

Assistant, not certification engine

  • We do not promise that every regulator will accept your outputs.
  • We do not bypass your internal privacy or security review.
  • We require a named human approver before issuing clean_file bundles.
  • You can purge originals immediately after export—or keep encrypted copies for 90 days by default.
  • We block training on customer uploads unless a separate written addendum says otherwise.
Operational note: If you operate in healthcare or finance, pair CleanRecordsHQ with your existing compliance program. The product helps you redact—it does not attest.
  • Free scan on 25 pages or 500 rows
  • Review every redaction before export
  • Clean PDF, CSV, and redaction report