Learn how we safeguard your documents, reports, and payments. Our platform enforces Turnitin's Non-Repository Mode and a strict 24-hour cache lifecycle.
Our platform operates through an official integration with Turnitin's Instructor network. All files uploaded for similarity analysis are scanned in Non-Repository Mode:
• Comparison: Documents are compared against billions of indexed web pages, student papers, journals, and publications. • Zero Storage: Your file is parsed dynamically in-memory and compared. It is never added to the Turnitin global database. • Protection: Since the file is not stored, scanning your document here will not trigger a self-plagiarism flag when checked by university systems later.
We implement advanced encryption protocols to secure data during transfer and storage:
• In-Transit: All communication between your browser and our servers is encrypted using TLS 1.3/HTTPS protocol. • At-Rest: Uploaded documents and generated reports are stored in encrypted cloud caches using AES-256 algorithms. • Passwords: User passwords are encrypted using bcrypt hashing functions, preventing raw access even in database reads. • Session Management: User sessions are managed using securely signed JSON Web Tokens (JWT) with short expiration periods.
To protect your intellectual property, we enforce a strict automated data deletion lifecycle:
• Automatic Deletion: All uploaded files, analysis results, and PDF reports are permanently deleted from our cache database exactly 24 hours after submission. • Manual Deletion: You can instantly and permanently delete any scan history item manually by clicking the trash icon in your dashboard. This immediately deletes the file, PDF, and database log. • No AI Training: We do not retain, sell, or use your uploaded documents to train machine learning or AI models.
Our servers are shielded behind high-performance cloud firewalls and rate limiters:
• Cloudflare WAF: We route traffic through Cloudflare Web Application Firewall to block DDoS attacks, SQL injection, and cross-site scripting (XSS). • Rate Limiting: Strict rate limits are enforced on sensitive API routes (e.g., login, registration, password resets, and file scans) to prevent brute-force abuse. • Environment Isolation: File processing and report generation run in isolated sandbox environments to prevent cross-contamination.
Access to data is restricted strictly to authorized users:
• Ownership: Only the user who uploaded a document can access its details or download its similarity reports. • Administrative Access: Administrative access to our database is strictly limited to authorized system developers via secure VPNs and two-factor authentication (2FA). • Account Isolation: Client database records are isolated at the database level to prevent unauthorized cross-tenant access.
We align our operations with global compliance guidelines:
• Frameworks: Our security program is modeled in alignment with SOC2 Type II and ISO 27001 security standards. • Disclosures: We welcome security researchers to audit our platform. If you discover a vulnerability, please report it responsibly by emailing hello@similarfy.com. We will investigate and remediate verified bugs promptly.
If you detect any security loophole or vulnerability in our platform, please notify our core security team immediately to help us address it responsibly.
Email: hello@similarfy.com