How your data is handled

This page follows one document through Ressura, from upload to finding. It is written for the reviewer at your lender or investor as much as for you. The binding words are in the Security Statement, the Privacy Policy and the Data Processing Agreement; this page explains them in plain words.

What Ressura holds

Ressura holds three kinds of information about your company. First, the documents in your Data Room and the rows a Connection brings in. Second, what Ressura works out from them: the values it extracts, the Records it builds and the findings it raises. Third, the account details of the people you invite: a name, an email address and the role each person chose. Members and roles explains the roles.

Nothing is collected that the product does not use. Ressura does not sell personal information. The Cookie Statement lists every cookie and tag the site and the app set, the one advertising tag among them, and how to turn them off.

How a document is stored

A document goes into your company's Data Room and nowhere else. It is encrypted on the way in, using TLS, and encrypted where it rests, using AES-256 or an equivalent. Each company's data is kept apart from every other company's, so one customer can never reach another's documents. The database enforces that separation on every row, not only the app's own code.

What reads a document

Two things read a document: code and a model. The model does the reading a person would do. It finds the price, the date, the parties and the quantities in the text. Code does the arithmetic. Every dollar figure in a finding is computed by code from the extracted values and your company's own agreements, so a figure can always be recomputed and traced.

Model calls go through Vercel's AI Gateway in the United States with zero data retention. The provider answers and keeps nothing. Your documents are never used to train Ressura's models or anyone else's, and every provider Ressura uses is bound to the same rule in writing.

What a Connection may do

A Connection brings documents and rows into the Data Room. Only an admin can connect, sync or disconnect one. Everything a Connection delivers keeps its origin, so it is never confused with a file a person uploaded. The outside systems you connect, such as Xero or Google Drive, remain your own providers under your own agreements with them.

What is written down

The activity ledger is the record of the changes that matter: an edit to Organisational context, a change to a Control, a disposition on a finding, a disconnect, a deletion and a change to a member's role, each with who made it and when. The ledger only grows. While the company exists, nothing in it can be edited or removed, not even by Ressura. You will find it under Activity in Settings.

Where the rules are set

The Security Statement describes the controls in force. The Data Processing Agreement is the binding contract for personal data in your documents, and the Privacy Policy covers what Ressura holds about you as a person. Ressura is working toward SOC 2 and is not yet certified; no page on this site says otherwise.

Where your data lives names the region and the providers. Who can see what covers roles, sharing with a lender or investor, and Ressura's own staff.