Benchmarks: Answer 99.16% of DocVQA Without Images in QA: Agentic Document ExtractionRead more

LandingAI ADE Security and Compliance: SOC 2 Type II, GDPR, HIPAA, ZDR, and BAA

Share On :

LandingAI Agentic Document Extraction (ADE) is SOC 2 Type II compliant, GDPR-compliant through a dedicated EU deployment on AWS Ireland, and supports HIPAA processing when Zero Data Retention and a Business Associate Agreement are both active.

Certifications at a Glance

FrameworkStatusCondition
SOC 2 Type IICompliantIndependently audited against AICPA trust services criteria
GDPRCompliantEU deployment on AWS EU (Ireland)
HIPAASupportedRequires ZDR enabled plus a signed BAA
EU-U.S. Data Privacy FrameworkIn progressCertification underway

SOC 2 Type II

  • Independently audited and verified against the AICPA trust services criteria for security, availability, and confidentiality.
  • Type II assesses controls over a sustained period rather than at a single point in time, showing that controls operate consistently.
  • Request the SOC 2 report through the Trust Center.

GDPR and EU Data Residency

  • The EU deployment stores and processes all data within the EU, on AWS EU (Ireland).
  • Account and Playground: ade.eu-west-1.landing.ai
  • API keys are region-specific, so an EU key authenticates against the EU deployment and a US key against the US deployment.
  • Pricing is identical across both regions.
  • LandingAI is working toward certification under the EU-U.S. Data Privacy Framework.

HIPAA and the BAA

Processing Protected Health Information requires both conditions active at once:

  1. Zero Data Retention enabled for the organization.
  2. A signed Business Associate Agreement in place with LandingAI.
  • LandingAI maintains the administrative, physical, and technical safeguards HIPAA requires for PHI.
  • Enable ZDR first. The BAA request form appears on the Organization Settings page once ZDR is active.
  • Both are available on the Team and Enterprise plans, in the US and EU regions.

Zero Data Retention

  • With the ZDR option enabled, customer data is not persisted beyond processing.
  • Your data is used exclusively to perform the operation you request, such as parsing or extracting a document.
  • Processing begins when LandingAI receives your request and ends when the output is returned to you.
  • LandingAI does not use your data for training or improving its models when ZDR is active.
  • ZDR is opt-in. Without it, retention follows your agreement terms, and data may be used to provide and improve LandingAI services under the Terms of Service.
  • Once enabled, ZDR applies to direct API calls and to the Python and TypeScript libraries. A separate setting extends it to the Playground.
  • To turn ZDR off after enabling it, contact support@landing.ai.

Availability

RegionData locationPlans
USAWS US (Ohio)Team and Enterprise
EUAWS EU (Ireland)Team and Enterprise

Once ZDR is enabled, it covers every call regardless of how the document is submitted, including asynchronous jobs.

Data Handling by Deployment

DeploymentWhere processing happensZDRUsed for training
ADE SaaS, USAWS US (Ohio)Team and EnterpriseNo with ZDR; per your agreement without
ADE SaaS, EUAWS EU (Ireland)Team and EnterpriseNo with ZDR; per your agreement without
ADE in your VPCYour own AWS, Azure, or GCPInherent to the deploymentNo
ADE on SnowflakeLandingAI-hosted serviceCannot be used with ZDR enabledPer your agreement
  • In a VPC deployment, ADE maintains zero data retention because it is on your VPC. You own retention controls inside your infrastructure and across any subprocessors you integrate.
  • The ADE Snowflake app sends staged files to the LandingAI-hosted service for processing and returns results into Snowsight. It cannot be used when ZDR is enabled in your organization, so organizations requiring ZDR should call the API or client libraries directly.

Security Controls

All items below are documented on the security and compliance page.

  • Encryption: TLS 1.2 or higher in transit, AES-256 at rest.
  • Organization scope: an organization holds your credits, members, API keys, files, and settings. Explore supports one user; Team and Enterprise support unlimited members.
  • Data segregation: your data is kept logically separate from other customers' data in the multi-tenant architecture.
  • Access control: ADE organizations use two member roles, Developer and Admin. Both process documents and create API keys. Admins additionally revoke other members' API keys, invite and remove members, change roles, manage billing, and update the organization name. SSO through SAML 2.0 and OpenID Connect is available on Enterprise.
  • Zero-trust network: every access request requires strict verification, including MFA and least-privilege enforcement.
  • Audit logs: comprehensive, immutable records of critical user and system activity, actively monitored by the security team.
  • Infrastructure: AWS serverless within an isolated VPC, with independent third-party penetration testing, continuous vulnerability scanning, DDoS mitigation, and automated backups with tested recovery procedures.
  • Subprocessors: all are security-assessed before use, and the current list is published at trust.landing.ai/subprocessors.
  • Organizational: employee security training, background checks, patch management through weekly release cycles, and a tested incident response plan.

How to Enable Compliant Processing

Enable ZDR. Users on the Team and Enterprise plans turn ZDR on from the Organization Settings page in the ADE app. A checkbox during activation controls whether ZDR also applies to Playground uploads. For current step-by-step instructions, see the ZDR documentation.

Request a BAA. Enable ZDR first, then submit the BAA request form that appears on the Organization Settings page once ZDR is active. Both must be in place before any PHI is processed.

Route traffic to the EU. Create an account at ade.eu-west-1.landing.ai and generate an EU API key there. API keys are region-specific. For the EU base URL and library configuration, see the EU documentation.

FAQ

Is LandingAI SOC 2 Type II compliant?

Yes, independently audited against the AICPA trust services criteria for security, availability, and confidentiality. Request the report through the Trust Center.

Does ADE support HIPAA-compliant document processing?

Yes, when ZDR is enabled and a signed BAA is in place. Both must be active before any PHI is processed.

What does Zero Data Retention mean exactly?

With the ZDR option enabled, customer data is not persisted beyond processing. Your data is used exclusively to perform the operation you request, and processing ends when the output is returned to you. LandingAI does not use your data for training or improving its models when ZDR is active.

Which plans include ZDR?

Team and Enterprise, in both the US and EU regions. See Plans & Billing.

Is ADE GDPR compliant?

Yes, through a dedicated EU deployment on AWS EU (Ireland) where all data is stored and processed within the EU, with region-specific API keys and endpoints.

Can ADE run inside our own cloud?

Yes, as a containerized application in a customer-managed VPC on AWS, Azure, or GCP, where LandingAI has no access to your data.

Does the ADE Snowflake app keep data inside Snowflake?

No. Processing happens on the LandingAI-hosted service, with staged files sent for parsing and results returned into Snowsight. The app cannot be used when ZDR is enabled. Organizations that require data to stay in their own environment should choose the VPC deployment.

Where do I find the SOC 2 report and subprocessor list?

The SOC 2 report is available on request through the Trust Center, and the subprocessor list is published at trust.landing.ai/subprocessors.