Trust center
Security at DocoMatic
Public entities trust us with the documents they publish. This page states what our controls do today, what is still being built, and what we cannot give you yet — so your procurement and IT-review teams can judge for themselves.
Last updated: September 16, 2026Version 1.0
US data residency
DocoMatic is designed to process and store customer documents only in the United States: in AWS US East (N. Virginia, us-east-1), with encrypted backups in AWS US West (Oregon, us-west-2). Our production environment is still being set up; this page will state the deployed configuration once it is live. The marketing site you are reading has no write access to any customer data store.
We do not offer a Canadian region. Canadian customers are told during onboarding that their data is stored in the United States.
Encryption
In transit: production traffic is designed to be served only over TLS 1.2 or higher. Our API already sends HTTP Strict Transport Security headers so browsers refuse plain HTTP.
At rest: documents, outputs and backups are designed to be encrypted with AES-256 through AWS KMS in production.
Dedicated per-tenant or customer-managed encryption keys are not offered.
Production secrets are designed to live in AWS Secrets Manager. Development configuration is kept out of source control.
Tenant isolation
Every database row is scoped to a tenant, enforced with row-level security plus application-level scoping.
We run a dedicated cross-tenant test suite that attacks our core tenant-scoped endpoints — documents, download links, credits, members, workspaces, invitations and monitoring — with another tenant's credentials, and a test that fails if any table holding tenant data lacks enforced row-level security.
Every upload is scanned for malware with ClamAV before it is processed, and if the scanner is unavailable the file is not processed. Document parsers do not yet run in network-isolated, resource-limited sandboxes; that hardening is still to be done.
Retention and deletion
Our retention policy is set per plan: source files and outputs are kept for 30 days on the free trial, 1 year on Starter, 3 years on Growth, 7 years on Scale, and on a schedule agreed in the contract on Enterprise. Automatic deletion at the end of these periods is not switched on yet.
Deletion on request: email support@docomatic.ai. Our operations team carries out the deletion and can give you a record of what was removed. Self-serve deletion and downloadable deletion certificates are not available.
Export: there is no self-serve export of a whole account. Documents, remediated outputs and verification reports can be downloaded from the app, and we help with a bulk export on request.
Free-tool uploads are deleted within 24 hours by a storage lifecycle rule, and are not used to train models.
The same periods and the model-training position are set out in the Privacy Policy; deletion at the end of an agreement is in the Data Processing Agreement.
Sub-processors
We use a small number of infrastructure and service providers to run DocoMatic. The table below is the current list.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage, and backups | United States |
| Stripe | Payment processing and invoicing | United States |
| AI model providers | Image description for alt text, used only under a contract that forbids training on your documents and keeps no copy of them; without one, our own software is used and nothing leaves our systems. Each customer organization can also turn outside AI off entirely in its settings, and then only our own software is used. | United States |
| Cloudflare Turnstile | Automated-abuse check on public forms. Loaded only when unusual activity from your network triggers it | Global network |
Current as of September 16, 2026.
When this list changes, we update this page and its date.
This list and our Acceptable Use Policy are consistent: the AI providers above process data in the United States only, and DocoMatic does not currently support personal information that is subject to the EU or UK GDPR.
How we handle security
Our written security policies cover access control, acceptable use, data classification and handling, encryption, incident response, business continuity and backup, vendors and sub-processors, change management and secure development, vulnerability management, and data retention and deletion. Each policy has an owner and is reviewed at least once a year.
Security documentation and our questionnaire answers are available on request. Contact us and choose the security topic.
Assurance and documentation
No third-party penetration test has been performed yet. We will say so on this page when one has.
We have written answers to the questions that public-sector security reviews usually ask, and we share them on request. If your review uses a specific questionnaire, we complete it for you individually.
VPAT/ACR: we have not yet published an Accessibility Conformance Report for the DocoMatic application. A working draft of our own evaluation is available on request. Its known accessibility issues are listed in our accessibility statement. Questions go to support@docomatic.ai.
Vulnerability disclosure
If you believe you have found a security issue in DocoMatic, email security@docomatic.ai. We acknowledge reports within 2 business days and keep you informed through resolution. A security.txt file is published at the standard well-known path.
Safe harbor: we will not pursue or support legal action against researchers who make a good-faith effort to follow this policy — test only against your own accounts or our public tools, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure.
The acknowledgement time is a published commitment in Service Levels and Support, section 6, and the Acceptable Use Policy points good-faith reports to this process.
Procurement pack (self-serve)
What purchasing and IT-review teams usually ask for, with an honest status for each. The Data Processing Agreement and the accessibility statement are available now, and our security questionnaire answers and IRS Form W-9 are available on request. The other items are not available yet.
- On request
IRS Form W-9
Taxpayer identification for vendor onboarding.
Request a W-9 - Not yet available
Sole-source justification template
A starting point for procurement teams that need to document a sole-source purchase.
- Not yet available
VPAT / Accessibility Conformance Report
Accessibility conformance report for the DocoMatic application. Not published yet. A working draft of our own evaluation is available on request; it is not a final report.
Request the draft - On request
Security questionnaire answers
Written answers to common security-review questions, together with our security policies. We complete a specific questionnaire, such as HECVAT Lite, individually.
Request them - Not yet available
Sample invoice
Example invoice showing line items, credits, and tax handling, so your budgeting and AP setup start from the real format.
- Available now
Data Processing Agreement (DPA)
Our Data Processing Agreement (version 1.0) is published, including FERPA school-official terms for education customers. A HIPAA Business Associate Agreement is available on request and must be signed before any protected health information is uploaded.
Read the DPA - Available now
Accessibility statement
Our public conformance statement for this site, with testing methodology and known issues.
Read the accessibility statement
Need something for a review that is not listed here? Email support@docomatic.ai and we will tell you what we can provide.
How public entities pay — purchase orders, invoices paid by ACH, tax-exempt certificates — is on the pricing page.
For your review
Ask for what your review needs.
Our written security policies and questionnaire answers are shared on request, and we complete a specific questionnaire for you. If you would rather talk it through first, book a 20-minute demo.