Security & Data Handling
Duplocate is built around one core principle: minimize your data exposure as much as possible.
The entire system is intentionally designed to be simple, transparent, and low-risk.
How Your Data Is Handled
- You upload your file securely over HTTPS.
- We process it immediately to find potential duplicate payments.
- We generate a report for you.
- Your raw file is permanently deleted within seconds of processing.
- Your report is available for only 15 minutes, then automatically deleted.
- No accounts. No long-term storage. No persistent identifiers.
Our Core Data Protection Principles
-
Temporary Processing Only — Your file is processed in secure, temporary
environments and never moves into long‑term storage.
-
Immediate Deletion — Your original file is permanently deleted within seconds
of processing. No backups are retained.
-
Very Short Report Retention — Your report is available for only 15 minutes
before being permanently deleted.
What We Keep vs What We Don’t
We Keep (Anonymized Only)
- Common invoice number patterns
- Statistical patterns in vendor names
- Aggregate duplicate payment behavior
We Never Keep
- Your company name
- Vendor names or details
- Invoice amounts or dates
- Any personally identifiable information
Why This Approach Is Strong
Many larger audit firms need complex compliance frameworks because they retain data for long periods.
Our approach is deliberately different: less data = lower risk.
Technical Security Measures
- All data is transmitted using strong encryption (HTTPS/TLS 1.2+).
- Files are processed in isolated, temporary environments.
- No human access to uploaded files during normal operation.
- No uploaded data is used for AI training or model development.
- Automated systems permanently delete data according to strict timelines.
- We follow security best practices appropriate for sensitive financial data.
SOC 2 Readiness Overview
Organizations evaluating Duplocate against SOC 2 principles can reference the following
readiness checklist. These are the types of controls commonly implemented in SOC 2‑aligned
environments.
1. Access Control
- Multi‑factor authentication (MFA) enforced across systems
- No shared credentials
- Role‑based access permissions
- Timely deprovisioning of access
2. Logging & Monitoring
- Authentication events logged
- File uploads logged
- Processing and scan events logged
- Alerts for anomalous or suspicious activity
3. Data Handling
- Encryption at rest (e.g., S3, databases)
- Encryption in transit (TLS 1.2+)
- Defined data retention timelines
- Secure deletion procedures
4. Infrastructure Security
- Hardened servers and baseline configurations
- Firewall and network segmentation controls
- No publicly accessible storage buckets
- Restricted administrative access with MFA
5. Governance & Policies
Duplocate maintains documented policies covering:
- Information security
- Change management
- Vendor management
- Incident response
- Disaster recovery and business continuity
- Acceptable use
- Risk assessment
6. Vendor Management
Duplocate maintains an inventory of third‑party services, such as:
- Cloud infrastructure providers (e.g., AWS)
- Content delivery or security networks (e.g., Cloudflare)
- Logging and monitoring platforms
- Email or notification providers
- Third‑party libraries or dependencies
7. Security Awareness & Training
Standard SOC 2 practices include:
- Annual security awareness training
- Phishing and social engineering awareness
- Policy acknowledgment and periodic review
Contact
support@duplocate.com
Duplocate Inc.
1800, 330 5th Ave SW
Calgary, AB T2P 0L4
Canada