citrus

Security at Citrus

Last updated: 14 July 2026

Citrus reads your supplier contracts, so we hold ourselves to the standard your security team would. This page is written for that review: what we do with your data, where it lives, and what we don’t have yet, stated plainly, so you can forward it instead of sending a questionnaire.

One thing up front: we are an early-stage company and we do not yet hold SOC 2 or ISO 27001 certification. Rather than imply otherwise, this page tells you exactly what we do, with nothing rounded up.

The Service is operated by Citruscan Pty Ltd (ACN 698 868 870, ABN 33 698 868 870), Sydney, Australia.

The short version

  • Your contracts are never used to train AI models, not by us, and our AI provider is contractually barred from doing so.
  • Your contracts are visible only to you. Tenant isolation is enforced at the database layer.
  • Saved analyses, including the contract text, live in your private library and are deleted on request.
  • Everything is encrypted in transit and at rest.
  • We don’t yet hold SOC 2 or ISO 27001; the infrastructure providers we run on do. Details below.

1. Where your data lives

Your documents and saved analyses are stored in the Asia-Pacific region (Tokyo, Japan), across every plan. Contract text is also sent to our AI provider in the United States at analysis time (see section 3). Some of our other service providers process limited information outside Australia in the course of providing the Service, consistent with Australian Privacy Principle 8. The full list is in section 5. If you need a specific storage region, talk to us.

2. Encryption and access

Data is encrypted in transit (TLS) and at rest. You can sign in with Google or with an email and password; passwords are managed by our authentication provider and stored only as salted hashes, never in plain text, and never on our own servers. Tenant isolation is enforced with row-level security at the database layer, so one customer’s contracts are never visible to another.

3. AI processing and model training

Contract text is processed by Anthropic’s Claude, via their commercial API, to generate your analysis. Under those commercial terms, Anthropic does not use your contract text to train its models. We never use your contracts to train models either, and we never will without asking you first.

The only data that leaves your private account is our optional, off-by-default benchmark programme: if you expressly opt in, anonymised structured data points (never contract text, never party names) contribute to aggregated market benchmarks, as described in our Privacy Policy.

4. Retention and deletion

When you’re signed in, each completed analysis, including the contract text, is saved to your private library so you can reopen it, compare contracts, and export reports. It stays there until it’s deleted. There’s no self-serve delete button yet; email hello@citruscan.com and we’ll delete specific analyses, or your whole account, promptly, normally within a few business days, and confirm when it’s done.

One operational detail, for completeness: while an analysis runs, we keep a short-lived server-side copy of the result so an interrupted connection doesn’t lose your analysis. That copy is deleted as soon as the analysis is saved to your library, or automatically within 48 hours.

5. Who touches your data

We keep the list of providers short, and we’ll update this section if it changes:

  • Supabase (on AWS): database, authentication, and storage, in Asia-Pacific (Tokyo). SOC 2 Type II audited.
  • Anthropic: AI analysis via the commercial Claude API, in the United States. SOC 2 Type II audited and ISO 27001 certified; contractually barred from training on your data.
  • Vercel: application hosting and delivery. SOC 2 Type II audited.
  • Lemon Squeezy: payments, as merchant of record. Card details never touch our servers.
  • Resend: transactional email, for account and product emails.
  • Google: optional sign-in only.

6. What we never do

  • Sell your data, or share it with advertisers or brokers.
  • Train AI models on your contracts.
  • Show your contracts, or anything derived from them, to another customer.
  • Add your data to benchmarks without an explicit opt-in, and even then, never contract text and never party names.

7. Compliance, honestly

  • Certifications: We do not yet hold SOC 2 or ISO 27001, and we won’t badge-wash. They’re on our roadmap as the company grows. The providers we run on, our database, hosting, and AI providers, each hold SOC 2 Type II today.
  • Privacy law: We operate under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
  • Breach notification: If a data breach occurs that is likely to result in serious harm, we notify affected individuals and the OAIC without undue delay under the Notifiable Data Breaches scheme.
  • DPA: Business customers can send us their DPA to review and sign.

8. What we don't have yet

So you don’t have to ask: no SOC 2 or ISO 27001 certification yet, no self-serve deletion (email us, we do it for you), no SSO/SAML beyond Google sign-in, and a single storage region (Tokyo). If one of these is a hard requirement for your review, email us; we’d rather tell you where it sits on the roadmap than let a page imply it exists.

9. Questions or concerns

Security questions, DPA requests, or vulnerability reports: hello@citruscan.com. A human, the founder, reads every one.