DocUnlock: Security & Privacy
Protecting your data, and your peace of mind.
Employing top-tier solutions to safeguard your information, empowering your growth with unwavering confidence.
Protecting your information
SOC2 Compliance
We are SOC 2 certified. We undergo annual third-party audits to verify our security controls meet the highest industry standards.
GDPR / CCPA Supported
We support customer privacy obligations under GDPR and CCPA through secure data handling practices, access controls, and data protection measures.
Strong Encryption
Your data is encrypted at rest (AES-256) and in transit (TLS 1.2+), keeping your information private and secure at every stage.
Authentication
All accounts are protected by multi-factor authentication (MFA), with every login monitored for unauthorized access attempts.
Infrastructure
Hosted on Google Cloud and AWS with multi-region architecture, ensuring high availability, resilience, and business continuity.
Availability and Redundancy
Your data is protected by geographically dispersed redundancy zones, automated backups, and regularly tested disaster recovery plans.
Data Handling
Documents you upload are processed securely and not used for any purpose beyond your workflow. Only authorized personnel can access your data, and all access is logged and audited.
Penetration Testing
In addition to SOC 2 audits, we conduct annual third-party penetration tests to proactively identify and address vulnerabilities.
Privacy
All staff and partners are bound by strict confidentiality agreements and trained regularly on data protection and privacy compliance.
Access Controls
We enforce MFA and SSO across all systems, and restrict network traffic to authorized services only. Access is granted on a least-privilege basis and reviewed regularly.
Device Security
All company devices are managed, encrypted, and monitored. Access to production systems is restricted to authorized, secured devices only.
Vendor Security
We evaluate all third-party vendors against defined security standards before approval, including their access to customer data and production systems.
Vulnerability Management
We continuously monitor for vulnerabilities across our infrastructure and applications, prioritizing and remediating issues based on risk severity.
Backups
Customer data is backed up automatically and stored securely across multiple locations. Backups are tested regularly to ensure reliable recovery in the event of an incident.
AI Training Policy
Customer documents and data are never used to train AI models. We process customer data only to provide and improve the DocUnlock service.
Data Residency
For customers based in the United States, customer data is stored in secure cloud infrastructure located within the U.S. We apply strict access controls to protect customer information. If you have specific data residency requirements, please reach out to us.
Training
All staff complete security awareness training upon joining and on an ongoing basis, covering data protection, phishing, and secure handling of customer information.
Security contact
To report a security concern or request a data processing agreement (DPA), contact us at security@docunlock.com.