Last updated: September 27, 2026
Security
OCRs.ai is built for teams that upload sensitive documents and call production APIs. Operated by Guni Innovations Pte. Ltd., we focus on practical controls you can verify — not certification theater.
What we protect
Customer files, account credentials, API keys, and vector-database connection secrets. We encrypt data in transit (TLS) and apply encryption at rest for sensitive stored secrets. File content is processed to deliver OCR results and then retained only as needed to complete the job (see our Privacy Policy).
Controls
Multi-factor authentication
Accounts can enable MFA with authenticator apps (TOTP) and email verification codes, so a stolen password alone is not enough to sign in.
API keys
Programmatic access uses hashed API keys. Full key material is shown once at creation and is not retrievable afterward. Revoke keys anytime from the dashboard.
Encrypted vector-DB secrets
Connection credentials for your vector database are stored encrypted at rest. They are decrypted only when needed to push embeddings on your behalf.
Turnstile on auth
Cloudflare Turnstile protects signup, login, and related auth flows against automated abuse without friction for most real users.
Prepaid wallet
Billing runs on a prepaid wallet topped up via Stripe. Usage is metered per page or video-minute — no surprise invoices from unbounded API spend.
What we do not claim
We do not claim SOC 2, ISO 27001, or similar certifications on this page. If your procurement process requires a questionnaire, DPA, or subprocessor list, email hello@ocrs.ai.