Security Overview
Security Overview
This page describes how Uva Software, LLC, the company behind Scanii, protects customer content and account data. It is a summary; the contractual commitments are in our Terms of Service, our Customer Data Processing Addendum (https://docs.scanii.com/article/172-dpa, the “DPA”) and our Privacy Policy. Security questionnaires, our penetration test report and other documentation are available through our Trust Center at https://trust.scanii.com.
How Scanii handles your content
Processing regions
Scanii runs as independent, region-specific deployments. You choose the processing region by the API endpoint you call: US1 (Virginia, USA), EU1 (Dublin, Ireland), EU2 (London, United Kingdom), AP1 (Sydney, Australia), AP2 (Singapore) or CA1 (Montreal, Canada). File contents submitted to a region are processed and stored only in that region and are never moved to another region. See https://docs.scanii.com/article/161-endpoints-and-regions for the current endpoint list.
What we keep after analysis
- File contents are held only for the time needed to analyze them, typically milliseconds to seconds, buffered on encrypted storage, and are deleted when analysis completes. We never permanently store customer files and we never use them to train detection models.
- We keep an analysis result record in the processing region: detected content type, size, checksum, detection findings, timestamps, any custom metadata attributes you attached to the request, and, for fetch requests, the source and callback URLs you supplied with any embedded credentials removed. File names and declared media types sent with uploads are discarded; content type is determined by our own analysis.
- Result records are retained for up to 400 days and can be deleted at any time through the API (DELETE on the result and its processing trace). When an account is deleted, its result records are deleted within 30 days as described in the DPA.
- A limited set of job metadata is sent to our US-hosted control plane to provide result lookup and usage analytics: job, API key and account identifiers, detection findings, an error code, completion timestamp, processing duration, API type and version, the requesting client’s user-agent string, and processing host and region. Content type, size, checksum, file names, URLs and your custom metadata values never leave the processing region.
- Where metadata search indexing is enabled for an account or region, truncated cryptographic hashes derived from custom metadata values are indexed in the US-hosted search service so that results can be searched; the original values are never transmitted.
- When one of your users opens a specific job in the web portal, its details are read from the processing region on demand and are not stored outside it.
- We may retain content checksums within a processing region to avoid re-analyzing identical content. Checksums are not shared with third parties.
- For image analysis we may submit image content to Amazon Rekognition within the same processing region. Rekognition does not retain the content or use it for its own training.
Encryption
In transit, all traffic is encrypted with TLS 1.2 or 1.3 using certificates issued by AWS Certificate Manager; we target an A+ grade at ssllabs.com for scanii.com and api.scanii.com. At rest, content buffers, databases and object storage are encrypted with AES-256. Account passwords are hashed with bcrypt. API key secrets are stored hashed.
Infrastructure and operations
Hosting
All production systems run on Amazon Web Services in the regions listed above, in AWS data centers with the physical and environmental controls described at https://aws.amazon.com/compliance/data-center/controls/. AWS SOC and ISO reports are available on request.
Access control
Production access is granted only to personnel who need it for their role and requires single sign-on with multi-factor authentication; AWS console and API access require MFA, and the AWS root accounts are reserved for break-glass use and monitored. Everyone with access to source code or production signs a confidentiality agreement. Company devices use full-disk encryption, a password manager, MFA everywhere it is offered, and an endpoint detection and response (EDR) agent.
Monitoring and intrusion detection
Amazon GuardDuty runs in every region we operate, analyzing CloudTrail, VPC flow and DNS logs and alerting our on-call rotation through PagerDuty. CloudTrail audit logs are retained for approximately five years; application, access and security logs are retained for at most 90 days.
Vulnerability and patch management
Our services run as containers on AWS Fargate, so there are no long-lived servers to patch: operating system and runtime fixes are delivered by rebuilding our container images from current base images on a regular cadence and redeploying them. AWS Inspector scans our images continuously, and findings are triaged and remediated according to our Vulnerability Management Policy based on severity and exploitability. Third-party libraries used by our own code are included in the same image scans and are updated as part of regular development and when a vulnerability affecting them is disclosed.
Penetration testing and vulnerability disclosure
An independent security firm performs a penetration test of the Services at least annually; the report is available through the Trust Center. We also run a paid vulnerability disclosure program that has paid out for responsible disclosures over the years (https://docs.scanii.com/article/131-does-scanii-have-a-security-vulnerability-disclosure-program).
Software development
Work is tracked as GitHub issues with severity labels. Changes are made through pull requests with automated testing and review, are built and tested by our CI/CD pipeline, and are deployed to production using a ring-based rollout that limits the blast radius of a defect. Our build pipeline includes an automated license checker to prevent the accidental introduction of copyleft-licensed dependencies.
Backup and disaster recovery
Production databases and data stores are backed up on a daily, weekly and monthly rotation retained for 7, 30 and 90 days respectively, with point-in-time restore for databases. Backups are encrypted and stored in the same region as the system they protect. We test restores on a schedule. Our business continuity plan targets a recovery time objective of 48 hours and a recovery point objective of 24 hours for restoring file-processing capability; file contents are transient and are never migrated between regions, and any change to the processing locations of the Services would be notified to customers in advance as the DPA provides.
Compliance and privacy
Certifications and audits
Uva Software participates in the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. Data Privacy Framework. We are preparing for a SOC 2 examination and are not yet independently audited against SOC 2; our security policies, penetration test report and other evidence are available through the Trust Center, and the AWS SOC and ISO reports covering our hosting are available on request.
Data protection
We act as a processor (or sub-processor) for the content you submit and as a controller for your account data. Our DPA incorporates the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum as a fallback to adequacy, states our retention and processing locations, and lists our technical and organizational measures. Our Privacy Policy (https://docs.scanii.com/article/142-privacy-policy) describes our controller-role processing and maintains the current list of sub-processors and service providers.
Incident response
We maintain a documented incident response plan. If we become aware of a breach of security affecting your personal data, we notify affected customers without undue delay and in any event within 72 hours, as the DPA provides, and report on our status page at https://status.scanii.com.
Law enforcement requests
As stated in our Privacy Policy and the DPA, we may be required to disclose data in response to lawful requests by public authorities, including to meet law enforcement or national security requirements. Where permitted, we notify the affected customer and challenge requests we believe to be unlawful or overbroad.
Intellectual property
We claim no ownership of content submitted for analysis. Personnel must comply with all applicable laws regarding the handling of intellectual property owned by others.
Uva Software, LLC has operated Scanii since 2010 with a single focus: earning your trust through careful handling of your data and delivering a high-quality content identification service. Questions: security@uvasoftware.com.
Last updated September 8, 2026.