Security you can trust
PaperScorer is built with security at its core. We maintain rigorous standards to protect your data and ensure compliance with industry regulations.
Compliance & Certifications
Meeting the highest standards for data security and privacy
Built to SOC 2 Controls
PaperScorer follows SOC 2 framework requirements covering security, availability, processing integrity, confidentiality, and privacy.
Regular Audits
Independent security assessments validate our adherence to industry best practices and regulatory standards.
FERPA Ready
Our platform is designed to help educational institutions maintain FERPA compliance for student data.
How we protect your data
Multiple layers of security ensure your data stays safe
Encryption
All sensitive data and PII is encrypted. TLS and SSL protocols protect data transmission across all communication channels.
Secure Infrastructure
Hosted on Linode (Akamai) and AWS with database encryption mandated for all sensitive information.
Access Controls
Role-based access controls and multi-layered authentication mechanisms protect your data, with two-factor authentication available on accounts.
Monitoring & Logging
Comprehensive activity logging with real-time alerts for suspicious activities.
Vulnerability Scanning
Regular scanning across systems, networks, and applications to identify and address potential vulnerabilities.
Disaster Recovery
Data backup and disaster recovery procedures ensure business continuity and data protection.
Our security practices
Security isn't just technology—it's a culture. Our team follows strict protocols to ensure your data is protected at every level.
- Mandatory security awareness training for all employees
- Background checks including criminal screening and employment verification
- Confidentiality policies with regular audits
- Defined roles and responsibilities across development, security, and operations
- Secure software development lifecycle practices
- Regular penetration testing and security assessments

Maintained, not just launched
The most common way a platform becomes insecure is by sitting still on old runtimes and unpatched dependencies. Keeping the stack current is ongoing work, not a one-time project.
Current runtimes
The scanning engine runs on Java 21 and Spring Framework 6; the application platform runs on MySQL 8.4. Major version upgrades are treated as scheduled work rather than deferred indefinitely.
Dependency currency
Core libraries are kept on supported major versions — including OpenCV 4.13 for image recognition and AWS SDK v2 for cloud services — so security patches remain available to us.
Audit remediation
Findings from security audits are tracked and worked through in the codebase, not filed and forgotten. Remediation work is part of the normal release cycle.
Your data, your control
We believe in transparency and giving you full control over your data
Data Ownership
You own your data. We only process it to provide our services.
Data Export
Export your data at any time in standard formats.
Data Deletion
Request complete deletion of your data when needed.
Have security questions?
Our security team is here to help. Contact us for more information about our security practices or to request documentation.