*** September 2026 Major Release ***Read and watch

Aligning Document AI with Internal Security Policies

Share On :

Internal security policy reviews are a mandatory gate before enterprise teams can deploy new AI software that processes sensitive documents. Security teams evaluating LandingAI Agentic Document Extraction (ADE) need to know which specific configurations satisfy each policy domain: the exact controls, documentation sources, and deployment options that answer their review questions.

Identity and Access Management Policy Alignment

Enterprise identity and access management (IAM) policies require new software to support scoped credential management, role-based access, and integration with existing identity infrastructure.

API key scoping and revocation. On Team and Enterprise plans, organizations can create multiple named API keys and revoke individual keys without affecting others, supporting least-privilege credential management at the pipeline layer. A key used for contract processing can be revoked independently of one used for HR onboarding documents, and keys should be passed from a secrets manager or environment variable rather than hardcoded in source code.

Role-Based Access Control (RBAC). Organization and member management supports role-based membership with differentiated permissions per user and group; administrators can invite members, assign roles, remove access, and revoke pending invitations, enforcing separation of duties between a member who configures extraction schemas and an administrator who manages billing or enables Zero Data Retention.

Single Sign-On (SSO). On the Enterprise plan, SSO via SAML 2.0 and OpenID Connect (OIDC) lets organizations manage ADE access through an existing identity provider such as Okta or Microsoft Entra ID, enforcing corporate multi-factor authentication (MFA), session controls, and provisioning and deprovisioning workflows. Once SSO is enabled it becomes the only login method, so an employee removed from the identity provider loses ADE access through the same event.

Data Classification and Handling Policy Alignment

Internal data classification policies define how data at each sensitivity tier must be handled: where it can be processed, how long it can be retained, and whether a vendor can use it beyond the immediate transaction.

LandingAI ADE's Zero Data Retention (ZDR) option is a direct technical control for the highest sensitivity tiers: when the ZDR option is enabled for your account, customer data is not persisted beyond processing, this coverage extends across the entire platform including all subprocessors, and data is not used for training or improving models. Under standard non-ZDR configurations, data retention is governed by the terms of the customer service agreement. ZDR is available on Team and Enterprise plans in both the US and EU regions, with a separate setting controlling whether ZDR also applies to the Playground.

Encryption Policy Alignment

LandingAI ADE applies TLS 1.2 or higher for all data in transit and AES-256 for data at rest under non-ZDR configurations; these encryption standards referenced in SOC 2, HIPAA, and GDPR Article 32 documentation satisfy enterprise encryption policy minimums for both transit and at-rest controls. Under ZDR configurations no document data is written to storage, so at-rest encryption does not apply.

Network and Deployment Policy Alignment

LandingAI ADE provides multiple deployment configurations to address data residency, network isolation, and infrastructure ownership requirements, documented on the Security and Compliance page.

Policy RequirementADE Deployment OptionDetail
Data must remain within the EULandingAI-hosted EU regionEU region deployment on AWS Ireland (eu-west-1); data stored and processed within the EU
Data must not leave customer-controlled infrastructureContainerized VPC or on-prem deployment (Enterprise)Deployable inside the customer's own VPC on AWS, Azure, or GCP; no LandingAI access to documents during processing
Standard cloud deployment with ZDRLandingAI-hosted US regionAWS Ohio (us-east-2); ZDR available on Team plans and above

Contact LandingAI through the enterprise contact page to initiate a containerized VPC or on-prem deployment.

Third-Party Vendor Risk Policy Alignment

Internal vendor risk policies require new software vendors to demonstrate independent security certifications, provide contractual data handling commitments, and document subprocessor scope, with evidence available through the Trust Center.

SOC 2 Type II. LandingAI has completed an independent SOC 2 Type II audit covering security, availability, and confidentiality over a defined audit period; the audit report satisfies the vendor certification requirement in standard third-party risk questionnaires.

GDPR compliance. LandingAI is compliant with the General Data Protection Regulation (GDPR); EU data residency is available through the EU region deployment, and a Data Processing Agreement (DPA) is available for enterprise customers through the enterprise contact page.

HIPAA compliance. LandingAI ADE supports HIPAA-regulated processing when ZDR is enabled and a signed Business Associate Agreement (BAA) is in place; BAAs are initiated through Organization Settings after ZDR activation and are available on Team and Enterprise plans.

EU-US Data Privacy Framework. Certification is in progress; verify current status at the Trust Center before finalizing a vendor assessment that covers transatlantic data transfers.

Secure Development Lifecycle Policy Alignment

Enterprise security policies increasingly require vendors to demonstrate that security review is embedded in development rather than applied at release. LandingAI integrates security across the product development lifecycle from design and code review through testing and deployment, documented on the Security and Compliance page, with security controls covered by the SOC 2 Type II audit.

Policy Alignment Reference

Internal Policy DomainADE Configuration or ControlEvidence Source
IAM: least-privilege credential managementMultiple named API keys with individual revocation (Team and Enterprise)API key documentation
IAM: role-based accessRBAC with differentiated permissions per user and groupOrganizations and Members
IAM: identity provider integrationSSO via SAML 2.0 and OIDC (Enterprise); enforces corporate MFA and deprovisioningSSO documentation
Data handling: retention limitsZDR keeps customer data from being persisted beyond processing across all subprocessorsZDR documentation
Encryption: in transitTLS 1.2 or higherSecurity and Compliance
Encryption: at restAES-256 (non-ZDR); not applicable under ZDRSecurity and Compliance
Network: EU data residencyEU region deployment on AWS IrelandEU documentation
Network: infrastructure isolationContainerized VPC or on-prem deployment (Enterprise); no LandingAI access during processingEnterprise contact
Vendor risk: independent certificationSOC 2 Type II audit reportTrust Center
Vendor risk: contractual data handlingDPA (GDPR); BAA (HIPAA)Enterprise contact
SDL: secure development practicesSecurity integrated across the development lifecycleSecurity and Compliance

FAQ

Which plan tier is required to access the security controls needed for enterprise internal policy compliance?

ZDR, HIPAA support, multiple named API keys, and role-based member management are available on Team and Enterprise plans, while SSO and VPC or on-prem deployment are Enterprise-only, as detailed in the plan and feature breakdown. The Explore plan provides a single non-revocable API key with one user and does not support ZDR or organization member management.

Can LandingAI ADE integrate with an organization's existing identity provider rather than maintaining separate credentials?

Yes. On the Enterprise plan, LandingAI supports SSO via SAML 2.0 and OIDC with identity providers such as Okta and Microsoft Entra ID, letting organizations enforce existing MFA policies, session controls, and deprovisioning workflows for ADE access. Once SSO is enabled it becomes the only login method, so removing an employee from the identity provider revokes their ADE access through the same event.

What contractual instruments are available to satisfy vendor data handling obligations in internal security policies?

A Data Processing Agreement (DPA) is available for enterprise customers requiring a contractual instrument under GDPR Article 28. A Business Associate Agreement (BAA) is required and available for HIPAA-regulated Protected Health Information (PHI) processing on Team and Enterprise plans with ZDR enabled. Contact LandingAI through the enterprise contact page to initiate either agreement.

Does LandingAI ADE support internal policies that prohibit document data from leaving the organization's own infrastructure?

Yes. On the Enterprise plan, LandingAI offers ADE as a containerized application deployable in the customer's own VPC on AWS, Azure, or GCP, with no LandingAI access to documents during processing, and ZDR is supported in that deployment. For air-gapped requirements, confirm current support with LandingAI through the enterprise contact page.

Where should internal security teams direct a formal vendor review request for LandingAI?

The Trust Center contains the SOC 2 Type II audit report, compliance certifications, and real-time system status; the Security and Compliance page documents encryption standards, access controls, and data handling policies; and the ADE security and privacy documentation covers implementation details. For a DPA, BAA, or additional documentation, contact LandingAI through the enterprise contact page.