Skip to main content

Security and Data Handling (FAQ)

Data separation, sign-in and MFA, account controls, exporting your data, and what happens during an AI outage.

Written by Austin Carroll

Answers to common security and data handling questions from IT, security and compliance teams. For security documentation and policies, visit trust.hellowarrant.com.

How is our data kept separate from other companies?

Every file, scan, approval and setting in Warrant belongs to one company account. People only ever see and open content that belongs to their own company.

Within your company, folders, projects, roles and sharing settings decide who can see what. See Managing Roles & Permissions.

For how your data is handled by Warrant's AI, see How Warrant Uses AI.

How can our team sign in?

  • Email and password. Passwords must be at least 12 characters, and very common passwords are rejected.

  • Continue with Google or Continue with Microsoft, using your existing work account.

Repeated failed sign-in attempts are temporarily blocked, and people see "Too many sign-in attempts. Please wait and try again." Forgotten passwords can be reset from the login page. See How to Reset Password.

Can we require two-factor authentication?

Yes. An admin can switch on Multi-factor authentication (MFA) for the whole company in Settings, then Access & security. People who sign in with a password then confirm each sign-in with a single-use link sent to their email. They can choose to trust a device for 30 days. Google and Microsoft sign-ins rely on that account's own second check. See Two-Factor Authentication (MFA).

What happens to accounts nobody uses?

By default, Warrant deactivates accounts with no sign-in for 90 days. Admins can choose 30, 60, 90 or 180 days, or switch the policy off. People get an email warning 7 days before, and deactivation ends all of the account's active sessions. See Access & Security Settings.

Warrant can also flag sign-ins from locations that are too far apart to be possible. See Anomalous Login Detection.

Can we restrict access to specific IP addresses?

Not today. Warrant does not offer IP allowlisting for customer sign-ins. Two-factor authentication, dormant account deactivation and roles are the available controls.

Can we export our data?

Yes. You can export your content and records yourself at any time:

  • Files. Download one file, or select several and download them as a ZIP. Turn on Include all versions to get every version of an asset.

  • File details and activity. Turn on Include file details & activity for a CSV, Excel (XLSX) or PDF export of an asset's metadata, compliance scans, activity, approvals and comments. See Download & Export Files.

  • Reports. Export any report as CSV, Excel (XLSX) or PDF. See Reporting.

  • Asset audit trail. Use Export audit trail on an asset's audit trail for a CSV.

  • Policy audit trail. Admins can select Download CSV in Settings, then Policy tasks & audit trail. See Policy Tasks and the Policy Audit Trail.

  • Access review. When capability roles are enforced, admins can select Export access review in Settings, then Roles, for a CSV of who holds which roles.

What happens to our data if our contract ends or Warrant stops operating?

You can export your files, reports and audit trails yourself at any time, as described above. How data is returned or deleted at the end of a contract is covered by your agreement with Warrant. For details, contact [email protected].

Does Warrant detect personal or sensitive data before a file is uploaded?

No. Warrant does not scan files for personal or sensitive information before they are uploaded. Review files before uploading them, and remove anything that does not need to be in Warrant. If you want scans to flag certain kinds of information in your content, such as account numbers, an admin can add a custom policy for it. See AI Policies and Compliance Settings.

How does Warrant's AI handle our data?

See How Warrant Uses AI for what the AI does, how your data is handled, and how people stay in control of every decision. Warrant's AI Policy is available at trust.hellowarrant.com.

What happens if the AI service is temporarily unavailable?

  • Uploads still work. Your files are saved even if Warrant cannot read their contents straight away. If a file's contents were not read, use Re-Extract Data from the file's menu to try again.

  • Scans retry automatically. Short interruptions are retried on their own.

  • If a scan cannot finish, you see Scan failed. Run the scan again, or contact support if it keeps happening.

  • If only some checks finish, the results show Partial results and name the checks that did not complete. Those checks are not counted in the score. Select Rescan to include them.

  • Partial scans are never auto-approved. Content with an incomplete scan always waits for a person to review it.

Where can we find security documentation?

Visit trust.hellowarrant.com for Warrant's security and AI policies. For security questionnaires or anything not covered there, contact [email protected].

Did this answer your question?