DocoMatic

Trust center

Security at DocoMatic

Public entities trust us with the documents they publish. This page states what our controls do today, what is still being built, and what we cannot give you yet — so your procurement and IT-review teams can judge for themselves.

Last updated: September 16, 2026Version 1.0

US data residency

DocoMatic is designed to process and store customer documents only in the United States: in AWS US East (N. Virginia, us-east-1), with encrypted backups in AWS US West (Oregon, us-west-2). Our production environment is still being set up; this page will state the deployed configuration once it is live. The marketing site you are reading has no write access to any customer data store.

We do not offer a Canadian region. Canadian customers are told during onboarding that their data is stored in the United States.

Encryption

  • In transit: production traffic is designed to be served only over TLS 1.2 or higher. Our API already sends HTTP Strict Transport Security headers so browsers refuse plain HTTP.

  • At rest: documents, outputs and backups are designed to be encrypted with AES-256 through AWS KMS in production.

  • Dedicated per-tenant or customer-managed encryption keys are not offered.

  • Production secrets are designed to live in AWS Secrets Manager. Development configuration is kept out of source control.

Tenant isolation

  • Every database row is scoped to a tenant, enforced with row-level security plus application-level scoping.

  • We run a dedicated cross-tenant test suite that attacks our core tenant-scoped endpoints — documents, download links, credits, members, workspaces, invitations and monitoring — with another tenant's credentials, and a test that fails if any table holding tenant data lacks enforced row-level security.

  • Every upload is scanned for malware with ClamAV before it is processed, and if the scanner is unavailable the file is not processed. Document parsers do not yet run in network-isolated, resource-limited sandboxes; that hardening is still to be done.

Retention and deletion

Our retention policy is set per plan: source files and outputs are kept for 30 days on the free trial, 1 year on Starter, 3 years on Growth, 7 years on Scale, and on a schedule agreed in the contract on Enterprise. Automatic deletion at the end of these periods is not switched on yet.

  • Deletion on request: email support@docomatic.ai. Our operations team carries out the deletion and can give you a record of what was removed. Self-serve deletion and downloadable deletion certificates are not available.

  • Export: there is no self-serve export of a whole account. Documents, remediated outputs and verification reports can be downloaded from the app, and we help with a bulk export on request.

  • Free-tool uploads are deleted within 24 hours by a storage lifecycle rule, and are not used to train models.

The same periods and the model-training position are set out in the Privacy Policy; deletion at the end of an agreement is in the Data Processing Agreement.

Sub-processors

We use a small number of infrastructure and service providers to run DocoMatic. The table below is the current list.

Current sub-processors: provider, purpose, and location
ProviderPurposeLocation
Amazon Web ServicesCloud hosting, storage, and backupsUnited States
StripePayment processing and invoicingUnited States
AI model providersImage description for alt text, used only under a contract that forbids training on your documents and keeps no copy of them; without one, our own software is used and nothing leaves our systems. Each customer organization can also turn outside AI off entirely in its settings, and then only our own software is used.United States
Cloudflare TurnstileAutomated-abuse check on public forms. Loaded only when unusual activity from your network triggers itGlobal network

Current as of September 16, 2026.

When this list changes, we update this page and its date.

This list and our Acceptable Use Policy are consistent: the AI providers above process data in the United States only, and DocoMatic does not currently support personal information that is subject to the EU or UK GDPR.

How we handle security

Our written security policies cover access control, acceptable use, data classification and handling, encryption, incident response, business continuity and backup, vendors and sub-processors, change management and secure development, vulnerability management, and data retention and deletion. Each policy has an owner and is reviewed at least once a year.

Security documentation and our questionnaire answers are available on request. Contact us and choose the security topic.

Assurance and documentation

  • No third-party penetration test has been performed yet. We will say so on this page when one has.

  • We have written answers to the questions that public-sector security reviews usually ask, and we share them on request. If your review uses a specific questionnaire, we complete it for you individually.

VPAT/ACR: we have not yet published an Accessibility Conformance Report for the DocoMatic application. A working draft of our own evaluation is available on request. Its known accessibility issues are listed in our accessibility statement. Questions go to support@docomatic.ai.

Vulnerability disclosure

If you believe you have found a security issue in DocoMatic, email security@docomatic.ai. We acknowledge reports within 2 business days and keep you informed through resolution. A security.txt file is published at the standard well-known path.

Safe harbor: we will not pursue or support legal action against researchers who make a good-faith effort to follow this policy — test only against your own accounts or our public tools, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure.

The acknowledgement time is a published commitment in Service Levels and Support, section 6, and the Acceptable Use Policy points good-faith reports to this process.

Procurement pack (self-serve)

What purchasing and IT-review teams usually ask for, with an honest status for each. The Data Processing Agreement and the accessibility statement are available now, and our security questionnaire answers and IRS Form W-9 are available on request. The other items are not available yet.

  • On request

    IRS Form W-9

    Taxpayer identification for vendor onboarding.

    Request a W-9
  • Not yet available

    Sole-source justification template

    A starting point for procurement teams that need to document a sole-source purchase.

  • Not yet available

    VPAT / Accessibility Conformance Report

    Accessibility conformance report for the DocoMatic application. Not published yet. A working draft of our own evaluation is available on request; it is not a final report.

    Request the draft
  • On request

    Security questionnaire answers

    Written answers to common security-review questions, together with our security policies. We complete a specific questionnaire, such as HECVAT Lite, individually.

    Request them
  • Not yet available

    Sample invoice

    Example invoice showing line items, credits, and tax handling, so your budgeting and AP setup start from the real format.

  • Available now

    Data Processing Agreement (DPA)

    Our Data Processing Agreement (version 1.0) is published, including FERPA school-official terms for education customers. A HIPAA Business Associate Agreement is available on request and must be signed before any protected health information is uploaded.

    Read the DPA
  • Available now

    Accessibility statement

    Our public conformance statement for this site, with testing methodology and known issues.

    Read the accessibility statement

Need something for a review that is not listed here? Email support@docomatic.ai and we will tell you what we can provide.

How public entities pay — purchase orders, invoices paid by ACH, tax-exempt certificates — is on the pricing page.

For your review

Ask for what your review needs.

Our written security policies and questionnaire answers are shared on request, and we complete a specific questionnaire for you. If you would rather talk it through first, book a 20-minute demo.