Sheaf
What the work requires

Security and data handling

Documents carry the most sensitive material a business holds, and a document system is therefore a data-protection decision before it is a productivity one.

Every request is checked against the role that made it

Access is enforced per request, at the boundary, against the identity making it — not decided once at login and trusted thereafter, and not enforced only in the interface. A capability the interface does not offer you is a capability the server also refuses.

Roles separate what a person may do from what they decided. Those are deliberately different records: widening who may act should never quietly rewrite the history of who acted.

Records age out

Document data is retained on a fixed window and swept when it expires, rather than accumulating by default. Retention that depends on somebody remembering to delete things is not retention policy, it is an intention.

Traceability is a security property

Because every value resolves to a file, page and span, an incident question — what did this system actually hold about this person — has a concrete answer rather than an estimate. The same mechanism that makes an extraction checkable makes a disclosure request answerable.

Where documents are processed

Reading a document involves model inference, and inference runs on named infrastructure. The current list of processors and the regions they run in is available on request: privacy@sheaf.us.

Data-processing terms, including the standard agreement and any regional addenda, are handled through privacy@sheaf.us, which will return the current data processing agreement for signature.

Current posture

  • SOC 2 Pending. Status and expected date on request.
  • ISO 27001 On the roadmap, not certified.
  • HIPAA Workflow-ready. A BAA is available on request under an enterprise agreement.
Stated plainly

Pending is not certified and roadmap is not pending. These are written the way they are so that a security review does not have to discover it later; if a certificate is a hard requirement today, say so early and we will tell you where the work actually stands.

Reporting a vulnerability

Security reports go to security@sheaf.us and are acknowledged within 3 business days. Please include enough detail to reproduce; we will not pursue anyone acting in good faith under a reasonable disclosure timeline.

Put real document mess to the test. Send the bundle that currently ruins someone's afternoon, exactly as it arrived.

The rest of the site

Everything Sheaf claims, in writing

Document work is bought on specifics, so the specifics are on their own pages: what we do that a neighbouring category does not, one page at a time.

Against the alternatives

Sheaf vs LandingAI ADE

Excellent composable primitives with real visual grounding. Sheaf is the finished desk those primitives would need to be assembled into.

Sheaf vs Reducto

Agentic Deep Split and grounded citations. Sheaf adds the application, the approval and the coverage arithmetic on top.

Sheaf vs V7 Go

The other product that goes at completeness. Theirs checks a checklist you curate; Sheaf derives the requirements and matches documents as they land.

All comparisons

Ten head-to-head pages and one table — LandingAI, Reducto, V7 Go, Azure, Google, Textract, Instabase, Hyperscience, Rossum and the general models.