Last updated: September 27, 2026

Security

OCRs.ai is built for teams that upload sensitive documents and call production APIs. Operated by Guni Innovations Pte. Ltd., we focus on practical controls you can verify — not certification theater.

What we protect

Customer files, account credentials, API keys, and vector-database connection secrets. We encrypt data in transit (TLS) and apply encryption at rest for sensitive stored secrets. File content is processed to deliver OCR results and then retained only as needed to complete the job (see our Privacy Policy).

Controls

  • Multi-factor authentication

    Accounts can enable MFA with authenticator apps (TOTP) and email verification codes, so a stolen password alone is not enough to sign in.

  • API keys

    Programmatic access uses hashed API keys. Full key material is shown once at creation and is not retrievable afterward. Revoke keys anytime from the dashboard.

  • Encrypted vector-DB secrets

    Connection credentials for your vector database are stored encrypted at rest. They are decrypted only when needed to push embeddings on your behalf.

  • Turnstile on auth

    Cloudflare Turnstile protects signup, login, and related auth flows against automated abuse without friction for most real users.

  • Prepaid wallet

    Billing runs on a prepaid wallet topped up via Stripe. Usage is metered per page or video-minute — no surprise invoices from unbounded API spend.

What we do not claim

We do not claim SOC 2, ISO 27001, or similar certifications on this page. If your procurement process requires a questionnaire, DPA, or subprocessor list, email hello@ocrs.ai.