DataDoc Trust Center
Transparency is fundamental to trust. This page details how we protect your data, the security controls we maintain, and the compliance standards we operate against.
Security Overview
DataDoc implements defense-in-depth security controls across infrastructure, application, and data layers.
Data Encryption
AES-256 encryption at rest for all stored data. TLS 1.2+ enforced for all data in transit. Database-level encryption managed by Supabase with automatic key rotation.
Access Controls
Role-based access control (RBAC) with organisation-level isolation. Multi-factor authentication (MFA) supported. Row-level security (RLS) enforced at the database layer.
Infrastructure
Cloud-hosted on enterprise-grade infrastructure with automatic failover. EU data residency by default. Regular automated backups with point-in-time recovery.
Monitoring and Logging
Continuous monitoring of application and infrastructure health. Audit logging for all data access and administrative actions. Anomaly detection for security events.
Vulnerability Management
Regular dependency scanning and automated security updates. Static code analysis integrated into the development pipeline. Responsible disclosure programme in place.
Incident Response
Documented incident response plan with defined roles and escalation procedures. Commitment to notifying affected customers within 72 hours of a confirmed data breach, in line with GDPR Article 33.
Compliance and Certifications
We align our operations to recognised privacy and security frameworks. Below is the current status of each.
GDPR
Full compliance with the General Data Protection Regulation, including lawful basis documentation, data subject rights processes, and cross-border transfer safeguards.
ICO Registration
Registered with the UK Information Commissioner's Office as a data controller and processor.
SOC 2 Type II
Controls aligned to SOC 2 Trust Service Criteria covering security, availability, and confidentiality.
ISO 27001
Information Security Management System aligned to ISO 27001:2022 requirements and Annex A controls.
Cyber Essentials
Pursuing Cyber Essentials certification to demonstrate baseline security controls.
Sub-processors
The following third-party services process data on our behalf. We maintain Data Processing Agreements with each sub-processor and conduct regular due diligence reviews.
| Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | User accounts, uploaded documents, analysis results | EU (Frankfurt) |
| OpenAI | AI-powered document analysis and policy generation | Document content (processed, not stored) | United States |
| Stripe | Payment processing and subscription management | Payment details, billing information | United States / EU |
| Vercel | Application hosting and content delivery | Application traffic (no PII at rest) | Global CDN (EU primary) |
| Resend | Transactional email delivery | Email addresses, notification content | United States |
Data Handling
We process only the data necessary to deliver our services. Below is an overview of how customer data is managed throughout its lifecycle.
Data Processing
Documents uploaded for compliance analysis are processed by AI models to generate reports and recommendations. Document content is sent to the AI provider for analysis but is not used for model training or retained by the provider beyond the request lifecycle.
Organisation metadata (name, sector, frameworks) is stored to personalise analysis and recommendations.
Data Retention
Customer data is retained for the duration of the active subscription. Upon account closure or written request, all customer data including uploaded documents, analysis reports, and organisation data is permanently deleted within 30 days.
Backups are purged within 90 days of deletion from the primary database.
Data Portability
Customers can export their compliance reports, policies, and analysis data at any time through the platform's built-in export functionality (PDF, Excel). Bulk data export requests can be submitted via the contact page.
Data Isolation
Each organisation's data is logically isolated using row-level security (RLS) policies enforced at the database layer. Users can only access data belonging to their own organization. Administrative access is restricted and audited.
Policies and Documents
Our legal and privacy documentation is publicly available for review.
Penetration Testing and Audits
We conduct regular security assessments to identify and remediate vulnerabilities.
DataDoc undergoes periodic penetration testing conducted by independent third-party security firms. Findings are triaged, remediated, and verified within defined SLAs based on severity.
Automated dependency scanning runs on every deployment to detect known vulnerabilities in third-party libraries. Critical and high-severity findings are addressed before release.
Summary penetration test reports and security posture documentation are available to enterprise customers and prospects under NDA. To request access, please contact us via the link below.
Security Contact
For security-related enquiries, vulnerability reports, or to request compliance documentation, please get in touch.
security@datadoc.uk
For security enquiries and vulnerability reports