How HOLD handles your documents
Updated 17 August 2026
Your documents are stored by Supabase and processed by Google Document AI and Anthropic. Payments are handled by Stripe. These providers undergo independent security audits, including SOC 2, and publish their own compliance reports. Everything below is written the way we run it — what we can prove, what we produce on request, and what rests on contract, each labeled as what it is.
How your documents are sealed
Every document you upload is sealed with an encryption key unique to your account, and no person at HOLD has access to that key: no dashboard, no query, no download shows your files in readable form. The only system that can unseal a document is the automated processing pipeline itself, for the time it takes to read your lease — and every key use, and any change to who or what can use a key, is recorded in a log no one can edit. You can request that log any time — so you’re never trusting our word, you’re checking our receipt.
All traffic between you, HOLD, and every provider travels encrypted in transit (TLS 1.2+); documents are encrypted at rest.
HOLD’s code
HOLD’s server-side code runs inside Supabase, next to your data, so no separate HOLD server sits between you and it. The keys for Google Document AI and Anthropic stay in that environment — never in your browser, never on your machine. Every database read and write is made with your own login, under the same per-account rules the database enforces everywhere.
That infrastructure falls under Supabase’s audits. HOLD’s own code does not — here is what we do instead: it is scanned for vulnerabilities, leaked secrets, and unsafe dependencies on every update, and dynamically tested with OWASP ZAP against a running build before release. We assess the application against the OWASP Application Security Verification Standard (ASVS Level 1) and re-run that assessment at every major release — self-assessed, and labeled as such. Each customer’s data is isolated at the database layer, and that isolation is verified by automated tests on every update.
Who holds what
Supabase
Stores your documents, database, auth
- SOC 2 Type II
- ISO 27001
- HIPAA
- PCI DSS
Google Document AI
Reads scanned documents (OCR)
- SOC 1/2/3
- ISO 42001
- FedRAMP High
- PCI DSS v4.0
Anthropic
Reads documents (the AI)
- SOC 2 Type I & II
- ISO 27001:2022
- ISO 42001:2023
Stripe
Payments — HOLD never sees a card number
- PCI Service Provider Level 1
- SOC 2 Type II
- ISO 27001
Stripe’s SOC 3 report is public; its SOC 2 is available under NDA. Website analytics and hosting are handled by other providers, which touch no document and no payment — they are listed in our Privacy Policy.
What gets stripped out
Sensitive identifiers never reach the data HOLD keeps. Bank and account numbers, card numbers, SSNs and tax IDs, government IDs, and insurance policy numbers are removed by deterministic code — not by a model — before anything is written to your portfolio or shown on screen, and again when it is saved.
Your original file is never changed — the identifier is still in the document you uploaded. It just never appears in the data HOLD builds from it. Rents, dates, square footage and addresses are left alone.
Retention
Documents are read by Google Document AI, which does not store them after processing, and by Anthropic, which deletes them automatically within 30 days and never trains on them. We plan to move to a zero-retention agreement with Anthropic, at which point nothing is stored at all.
Training data
Your documents are never used to train a model. Not by HOLD, and not by Google or Anthropic — their commercial terms prohibit it, and those terms are published by them.
What you can check inside HOLD
Every value HOLD reports links back to the sentence it came from. Open any number and you get the quote, the page, and the original document — so the work is checkable one figure at a time, rather than taken on trust.
Settings holds an audit report you can generate any time, in seconds: every document’s read history — when it was read, by which model, at what cost, down to the $0.00 OCR line that proves a born-digital file never left for OCR at all — plus every change ever made to your data, and the exact list of the only services the app talks to.
Every read is recorded with the provider’s own request ID, so our record can be matched against theirs. Need the provider-side record? Request it with one click — no email, no support ticket — and it’s delivered right into your Settings.
What we commit to
Your portfolio is isolated. Each owner’s documents and data are separated from every other owner’s; nothing is pooled across accounts.
Where it lives. Your data is stored in Supabase’s United States region and backed up daily — a lost server never means a lost portfolio.
Signing in. Accounts and sessions are handled by Supabase Auth — HOLD never stores your password, and a session expires rather than lasting forever.
If something goes wrong. If a security incident ever affects your data, you hear it from us promptly and plainly — what happened, what was touched, and what we did about it.
Leaving. Your documents and the data read from them can be exported before you close the account — nothing is held.
Deleting. Delete a document and the file is removed from storage; your audit trail keeps the record that it existed and was deleted, and if you ever upload the same file again, its read history restores instantly — free.
Report a vulnerability
Found a security issue? Email security@holdcre.com. We respond within two business days, and we will never pursue anyone who reports in good faith.
Security questions
Send them through our contact form and they reach a person, not a queue — expect a reply within two business days.