Data Processing & Security Policy
Effective Date: May 2026 | Governing the Processing of Sensitive Client Financial Data
1. Purpose and Scope
This Data Processing and Security Policy (“Security Policy”) describes the technical and organizational measures Double Line employs to protect the confidentiality, integrity, and availability of data processed through its technology. It applies to all User Data uploaded through the Service, including client financial documents.
This policy is intended to give users confidence that we take the security of sensitive financial data seriously, and to provide sufficient transparency for users conducting vendor due diligence.
2. Data Processing Principles
We process all User Data in accordance with the following principles:
- Purpose Limitation: Data is processed only for the purposes described in our Terms of Use and Privacy Policy
- Data Minimization: We collect and retain only the data necessary to provide the Service
- Storage Limitation: Data is retained only as long as necessary, as described in our data retention schedule
- Integrity and Confidentiality: We apply appropriate technical and organizational measures to protect data
- Accountability: We maintain records of processing activities and conduct regular security reviews
3. Use of Third-Party Technology Providers
The Service utilizes third-party technology providers, including providers of cloud infrastructure, AI-assisted features, and other processing capabilities, to help deliver its functionality. Where User Data is processed by such providers, it is done solely to enable the Service and subject to agreements that require appropriate security and confidentiality standards. We do not authorize third-party providers to use your data for their own purposes, and we monitor these relationships on an ongoing basis.
3.1 AI Features
Certain features of the Service are powered by artificial intelligence provided through third-party API services. When these features are used, relevant data is transmitted to the AI provider solely to process your request and return a result. We access these AI capabilities through API agreements that include the following commitments:
- Your data is not stored on the AI provider’s servers beyond what is needed to process the immediate request
- Your data is not used to train, fine-tune, or improve the AI provider’s models
- Data transmitted is subject to the provider’s enterprise security and confidentiality obligations
These commitments mean that your data remains yours — it is used only to power the features you initiate within the Service and is not retained or repurposed by any AI provider.
Double Line also does not use your User Data to train public or shared artificial intelligence or machine learning models.
We may use information that has been de-identified and aggregated so that it cannot reasonably identify you, your organization, or your clients to improve the quality, reliability, accuracy, security, and functionality of the Service. Any such use is performed in accordance with applicable law and our contractual obligations to users.
3.2 Product Improvement and Model Evaluation
Double Line continually evaluates and improves the performance, reliability, and security of the Service.
To support these efforts, we may analyze operational metrics, system performance data, and information that has been aggregated and de-identified so that it cannot reasonably identify any individual, customer, or customer client.
We do not use Customer Data or User Data to train public or shared artificial intelligence models. Any internal evaluation, testing, or quality assurance activities involving customer information are conducted solely for the purpose of operating, maintaining, securing, or improving the Service and are performed under appropriate technical, organizational, and confidentiality safeguards.
4. Technical Security Controls
4.1 Encryption
- Data in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
- Data at rest: All stored User Data is encrypted using AES-256 encryption
- Database encryption: Database files containing User Data are encrypted at the storage layer
4.2 Access Controls
- Role-based access control limits employee access to User Data to those with a legitimate business need
- Multi-factor authentication (MFA) is required for all internal systems that process User Data
- Privileged access is logged, monitored, and subject to regular access review
- User accounts are isolated — no user can access another user’s data
4.3 Infrastructure Security
- The Service is hosted on enterprise-grade cloud infrastructure
- Network segmentation isolates processing environments
- Web application firewall protection against common attack vectors
- Intrusion detection and prevention systems monitor for anomalous activity
- Vulnerability scanning is conducted regularly; penetration testing is conducted annually
4.4 Secure Development
- We follow secure software development lifecycle (SDLC) practices
- Code changes are subject to peer review and automated security scanning
- Dependencies are monitored for known vulnerabilities
5. Organizational Security Controls
5.1 Employee Training and Background Checks
- All employees with access to production systems undergo background screening
- Security awareness training is conducted upon hire and annually
- Employees with access to User Data are subject to confidentiality obligations
5.2 Vendor Management
- All third-party vendors with access to User Data are subject to security review before engagement
- Vendors must agree to data processing agreements consistent with this policy
- Vendor security posture is reviewed at least annually
- Double Line periodically reviews the security commitments of vendors that process User Data, including commitments regarding confidentiality, data retention, and the use of customer information for artificial intelligence training or other secondary purposes
5.3 Incident Response
We maintain a documented incident response plan that includes:
- Defined escalation procedures and response team responsibilities
- User notification obligations: we will notify affected users of a data breach within 72 hours of discovery, or as required by applicable law
- Post-incident review and remediation process
- Coordination with law enforcement where required
6. Data Residency
User Data is stored and processed within the United States. We do not transfer User Data outside of the United States without your prior consent, except where required by law.
7. User Responsibilities
The security of your data is a shared responsibility. You agree to:
- Use strong, unique passwords and enable multi-factor authentication on your account
- Not share account credentials with unauthorized individuals
- Log out of the Service when not in use, particularly on shared devices
- Promptly notify us at legal@doubleline.io if you suspect unauthorized access to your account
- Ensure your devices used to access the Service are protected by up-to-date security software
8. Audit Rights and Certifications
We maintain the following to support user due diligence:
- SOC 2 Type II report (planned)
- Completed security questionnaires for enterprise users upon request
- Annual penetration test results summary (available upon request)
To request security documentation, contact: legal@doubleline.io
9. Data Backup and Recovery
- Encrypted daily operational backups are retained for 30 days
- Monthly encrypted archive backups are retained for 12 months
- Backups are stored in geographically separate data centers
- Recovery time objective (RTO): 4 hours | Recovery point objective (RPO): 24 hours
- Disaster recovery procedures are tested at least annually
10. Regulatory Compliance
While this Policy addresses our technical controls, users are responsible for ensuring their own use of the Service complies with all applicable laws, regulations, and professional standards. This includes but is not limited to any applicable data privacy laws and financial services regulations.
We recommend users consult with their legal or compliance advisors to determine what obligations apply to their specific use of cloud-based software services.
11. Policy Review and Updates
This Security Policy is reviewed at least annually and updated as necessary to reflect changes in our technology, operations, or the regulatory environment. Material changes will be communicated to users in accordance with our Privacy Policy.
12. Contact
For security concerns, to report a vulnerability, or to request security documentation:
Security Team | Double Line
legal@doubleline.io | 2006 N Sepulveda Blvd, #1019, Manhattan Beach, CA 90266
To report a security vulnerability, please use responsible disclosure by emailing our security team directly.