Account & BillingSecurity

Security and compliance questions

Straight answers for vendor security questionnaires - what we hold, what we are aligned with, and what DocEvent must not be used for.
Updated August 31, 2026

If you are filling in a vendor security questionnaire, the full detail lives on the Security page - encryption, access control, network security, monitoring, penetration testing, incident response and business continuity. This page answers the questions we are asked most often, plainly.

Certifications

We are not currently certified under SOC 2 or ISO 27001.

We maintain a comprehensive set of information security policies aligned with the ISO 27001 standard, reviewed at least annually, and our practices follow OWASP, NIST and FIPS guidance. "Aligned with" is the accurate phrase - please do not record us as certified.

If your procurement process needs something specific, email support@docevent.io and tell us what the questionnaire is asking for.

HIPAA and PCI DSS

The Cloud Products are neither HIPAA nor PCI DSS compliant, and our Terms of Service prohibit sending Sensitive Data through them. We do not act as a Business Associate and we cannot sign a BAA.

"Sensitive Data" is defined in the Terms and includes protected health information, payment card data, government ID numbers such as social security or driver's licence numbers, and the special categories of data in Article 9(1) of the GDPR.

If your files contain any of that, DocEvent's cloud service is not the right home for them. Self-Hosted runs the server on your own infrastructure, which changes the picture - talk to us about it.

Separately: we never store payment card data. Card details are captured and processed by a PCI DSS Level 1 certified payment provider, so cardholder data never reaches our systems.

GDPR

We offer a Data Processing Agreement that forms part of the Terms of Service, with DocEvent as Processor. Our incident policies are written to meet the notification duties in Articles 33 and 34.

Can DocEvent read my files?

The Simple FTP Service is designed so that we cannot. It streams data from the incoming SFTP or FTPS connection straight to the backend you choose - your own S3, Azure, GCS or S3-compatible storage - rather than storing it.

The Channels service is different, because routing a file means holding it briefly. Channel files sit in encrypted, non-public S3 buckets and are removed as soon as the file has reached all of its destinations, or the transfer has failed its retries, or the file is a day old - whichever comes first.

Read Access to customer data by DocEvent.io on the Security page for the full description.

Data residency

Services run in the region you create them in, and your files live in your storage account, so you choose where the data sits. See Static IP addresses and ports for the regions available and what to allowlist.

Reporting a vulnerability

There is a disclosure process on the Security page. If you have found something, please use it.