Built for Enterprise Trust

Security & Trust

How DocEnsure protects the documents you trust us with — encryption, retention controls, India data residency, isolated processing, and the certifications we're working toward.

Core security controls

Encryption at rest — AES-256

Every document and every database row is encrypted with AES-256. Encryption keys are managed by the cloud provider's KMS and rotated regularly.

Encryption in transit — TLS 1.3

All client and API traffic is protected by TLS 1.3 with strong ciphers. We enforce HSTS and reject deprecated protocols.

Isolated processing

Each document is processed in a short-lived, isolated container. The container is destroyed once the verification report is generated. No persistent processing host has access to your documents.

India data residency

Documents, reports, and account data are stored and processed in cloud regions inside India (Mumbai & Hyderabad). Customer documents are never transferred outside India without your explicit consent.

Least-privilege access

Production access is restricted to a small set of engineers via SSO with mandatory MFA. All access is logged and reviewed. Customer document content is not accessible to support staff except under explicit, time-bound consent.

Configurable retention

Default retention is 30 days; paid plans can shorten this to as low as 24 hours or extend it up to 365 days. Enterprise customers can require post-verification deletion under a Data Processing Agreement.

No training on your data

We do not train our AI models on your uploaded documents. Model improvements use either synthetic data, public datasets, or data submitted under a separate written research agreement with explicit consent.

Audit logs

Every verification, login, configuration change, and access to a forensic report is logged with the actor, timestamp, and source IP. Logs are retained for 12 months and available to enterprise customers on request.