Gatherwell

Security

You are being asked to put client bank statements through a supplier you have not heard of before. That is a reasonable thing to be careful about. This page is written so your security review is a link rather than an afternoon. There is also a completed short-form security questionnaire (PDF) you can hand straight to whoever asks.

Last reviewed September 2026. If something here is not enough for your review, ask and we will answer in writing.

Where your data is held

All application data and all client files are held in the European Union. The database and the application servers run in the EU, and file storage is an EU region of an S3-compatible object store. Backups stay in the EU. Nothing is replicated outside the EU or the UK.

A UK-region option is available on request for firms that need it.

Encryption

In transit
TLS 1.2 or better on every connection, including the client checklist page, the firm application, our inbound email endpoint and every call to a sub-processor. HTTP requests are redirected to HTTPS. HSTS is set.
At rest
AES-256 on database volumes, file storage and backups.
Integration credentials
Tokens for your Google Drive or OneDrive are encrypted with an application key held outside the database and are decrypted only inside the job that uploads your files. They are never written to a log, never shown in the interface and never returned by any interface we expose.

Access control

What we do with files that arrive

Every inbound file is scanned for malware before it is stored, its type is checked against its contents rather than its extension, images are re-encoded, and size limits are enforced. Files are never executed and are served back only through short-lived signed links. Raw inbound email is kept for 30 days so a failed delivery can be reprocessed, then purged.

Retention and deletion

Audit trail

Every change to a request and every access to a file is written to an append-only audit log with the actor, the action and the time. You can export your firm's log. We cannot alter it after the fact.

Sub-processors

These are the third parties that can process data on our behalf. We will give 30 days' notice before adding one.

Sub-processorPurposeData it can seeRegion
Hosting provider (EU)Application servers, database, backupsAll application dataEU
Object storage provider (EU)Client filesFiles your clients sendEU
Transactional email providerSending requests and reminders, receiving repliesMessage content and attachments in transitEU or UK
Error trackingApplication errorsStack traces only. File contents and message bodies are excluded by configuration.EU
StripeSubscription billingYour firm's billing contact and payment details. No client data.EU and US, under its own terms
SMS provider (from Phase 2, not yet live)Reminders by text in your firm's nameReminder text and mobile numbersEU or UK

Named providers are confirmed at contract. If your firm needs the specific legal entities and their data processing terms before signing, ask and we will send the list.

Artificial intelligence

There is no AI in the product today. When document classification arrives it will be opt-in per firm, no customer data will be used to train any model, prompts will be logged without file content, and account numbers will be redacted before anything is sent to a model. This paragraph will be updated before that ships, not after.

If something goes wrong

Assurance

Contact

Security questions and incident reports go to the founder directly and are answered by a person, not a form. Ask through the front page and mark it security.