Security & Data Handling

Duplocate is built around one core principle: minimize your data exposure as much as possible.
The entire system is intentionally designed to be simple, transparent, and low-risk.

How Your Data Is Handled

  1. You upload your file securely over HTTPS.
  2. We process it immediately to find potential duplicate payments.
  3. We generate a report for you.
  4. Your raw file is permanently deleted within seconds of processing.
  5. Your report is available for only 15 minutes, then automatically deleted.
  6. No accounts. No long-term storage. No persistent identifiers.

Our Core Data Protection Principles

What We Keep vs What We Don’t

We Keep (Anonymized Only)

We Never Keep

Why This Approach Is Strong

Many larger audit firms need complex compliance frameworks because they retain data for long periods. Our approach is deliberately different: less data = lower risk.

Technical Security Measures

SOC 2 Readiness Overview

Organizations evaluating Duplocate against SOC 2 principles can reference the following readiness checklist. These are the types of controls commonly implemented in SOC 2‑aligned environments.

1. Access Control

2. Logging & Monitoring

3. Data Handling

4. Infrastructure Security

5. Governance & Policies

Duplocate maintains documented policies covering:

6. Vendor Management

Duplocate maintains an inventory of third‑party services, such as:

7. Security Awareness & Training

Standard SOC 2 practices include:

Contact

support@duplocate.com
Duplocate Inc.
1800, 330 5th Ave SW
Calgary, AB T2P 0L4
Canada