Trust

Security & how we handle files

Visa Engine stores case files so you and your firm can prepare a petition or visitor checklist. This page restates how that works. It is not a certification badge, and it does not replace the Privacy Policy.

What we store

Depending on how you use the product, that can include account data from Google sign-in, case metadata (visa type, scores, notes), uploaded evidence files, preparation answers, drafts, signed letters returned through a signature link, and billing identifiers for paid plans. For each case you choose what is kept of an upload: the original file, only the evidence cut out of it as PDFs of its original pages, or only its extracted text. Upload only materials you are authorized to share with cloud processors.

How access works

Signed-in users reach their own cases. Firm cases use organization roles so attorneys, staff, and invited clients share one file. We use access controls appropriate to a cloud SaaS product. Protected routes still require authentication.

Transport and infrastructure

We use encrypted transport, access controls, and storage on reputable infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Who processes data

We use subprocessors to run the service — not to sell personal information:

  • Amazon Web Services (AWS) — hosting, compute, file storage, and backups, including the authentication and database we run on AWS with open-source Supabase (Supabase, Inc. does not receive your data)
  • Google — OAuth sign-in
  • OpenAI, and Anthropic's Claude models on Amazon Bedrock (run by AWS in its EU Regions) — extraction, analysis, drafting, and chat (via the Vercel AI SDK). We configure providers so submitted content is not used to train their general models, to the extent those terms are available to us; on Bedrock, Anthropic does not receive your content and we do not log requests.
  • Resend — transactional email, such as team invitations, signature requests sent to letter signers, and privacy-request notices
  • Stripe — subscription payments and the billing portal
  • PostHog (EU Cloud) — product analytics, error tracking, and session replay. In the signed-in app, recordings show layout and clicks only: all on-screen text and form inputs are masked, and document pages are not captured.

Retention and deletion

While your account is active we keep case and document data needed to provide the service. After you schedule account deletion, we soft-delete and then hard-purge account data after 30 days (you can reactivate within that window). Production database backups are retained about 30 days; migration scratch objects about 14 days. Residual copies may linger in those backups until they rotate. Stripe, PostHog, OpenAI abuse logs, and platform logs follow provider or counsel-approved schedules (see Privacy Policy).

If something goes wrong

If we become aware of a personal data breach affecting your information, we will notify you and relevant authorities where required by applicable law. Firm customers should also review the draft customer DPA for processor-to-controller notice language (pending counsel).

What we do not claim

We do not claim SOC 2, ISO 27001, or similar certifications on this page. We do not describe Visa Engine as bank-grade or attorney-grade security. For the binding privacy notice, read the Privacy Policy. Firm processor terms: draft DPA and subprocessor schedule.

Last reviewed: September 24, 2026. This page summarizes facts already in the Privacy Policy.