Security and compliance questions
If you are filling in a vendor security questionnaire, the full detail lives on the Security page - encryption, access control, network security, monitoring, penetration testing, incident response and business continuity. This page answers the questions we are asked most often, plainly.
Certifications
We are not currently certified under SOC 2 or ISO 27001.
We maintain a comprehensive set of information security policies aligned with the ISO 27001 standard, reviewed at least annually, and our practices follow OWASP, NIST and FIPS guidance. "Aligned with" is the accurate phrase - please do not record us as certified.
If your procurement process needs something specific, email support@docevent.io and tell us what the questionnaire is asking for.
HIPAA
DocEvent signs Business Associate Agreements. When the Simple FTP Service or Channels create, receive, maintain or transmit protected health information on your behalf, DocEvent is your business associate under the HIPAA Security Rule, and a BAA must be in place before any PHI moves. Email support@docevent.io to request one.
The architecture is what makes this workable: your files land in your own bucket, under your keys, and DocEvent holds configuration, hashed credentials and the audit log. There is no HHS "HIPAA certification" for software or vendors, and we do not claim one - the software supports your obligations, your risk analysis and policies complete the programme. For the regulatory background, read Does HIPAA require on-premises file transfer?. If your policy says file bytes must never transit a vendor at all, Self-Hosted runs the server in your own AWS account.
PCI DSS
The Cloud Products are not PCI DSS compliant, and our Terms of Service prohibit sending payment card data through them.
Separately: we never store payment card data for billing. Card details are captured and processed by a PCI DSS Level 1 certified payment provider, so cardholder data never reaches our systems.
GDPR
We offer a Data Processing Agreement that forms part of the Terms of Service, with DocEvent as Processor. Our incident policies are written to meet the notification duties in Articles 33 and 34.
Can DocEvent read my files?
The Simple FTP Service is designed so that we cannot. It streams data from the incoming SFTP or FTPS connection straight to the backend you choose - your own S3, Azure, GCS or S3-compatible storage - rather than storing it.
The Channels service is different, because routing a file means holding it briefly. Channel files sit in encrypted, non-public S3 buckets and are removed as soon as the file has reached all of its destinations, or the transfer has failed its retries, or the file is a day old - whichever comes first.
Read Access to customer data by DocEvent.io on the Security page for the full description.
Data residency
Services run in the region you create them in, and your files live in your storage account, so you choose where the data sits. See SFS Static IP addresses and ports for the regions available and what to allowlist.
Reporting a vulnerability
There is a disclosure process on the Security page. If you have found something, please use it.