What your security team will want to know
Written to answer a vendor questionnaire rather than to reassure in the abstract. If something you need is missing, ask and we will answer specifically.
How does TheDocs secure customer content?
TheDocs encrypts data in transit with TLS 1.2 or higher and at rest with AES-256, isolates each customer workspace logically, enforces role-based access control with optional SAML or OIDC single sign-on, records every content and permission change in an audit log, and lets customers choose whether their data lives in India, the European Union or the United States.
- TLS 1.2+ in transit, AES-256 at rest.
- Per-workspace logical isolation, enforced at the data layer.
- SAML 2.0 and OIDC SSO; SCIM provisioning on Enterprise.
- Point-in-time recovery within a 30-day window.
- Least-privilege internal access, reviewed quarterly.
- Customer content is never used to train shared models.
Encryption and network
- In transit
- TLS 1.2 or higher on every endpoint, including custom domains. HSTS is enabled and HTTP is redirected.
- At rest
- AES-256 on databases, object storage and backups.
- Certificates
- Custom-domain certificates are issued and renewed automatically; you never handle a private key.
- Secrets
- Application secrets live in a managed vault, rotated on a schedule and never in source control.
Access control
- Roles
- Owner, admin, author, reviewer and reader, assignable per project and per category.
- Single sign-on
- SAML 2.0 and OIDC from the Growth plan. Enforce SSO-only sign-in to disable password login entirely.
- Provisioning
- SCIM 2.0 on Enterprise, so leavers lose access when HR deactivates them, not when someone remembers.
- Reader access
- Public, sign-in required, IP-restricted, or limited to named partner accounts - configured per project.
Data handling and residency
- Residency
- Choose India, the European Union or the United States when the workspace is created. Content and backups stay in the chosen region.
- Isolation
- Every workspace is logically isolated. Queries are scoped at the data layer, not only in application code.
- Backups
- Continuous backup with point-in-time recovery inside a 30-day window. Restores are tested quarterly.
- Deletion
- On cancellation, content is retained for 30 days for export, then deleted from primary storage and purged from backups within a further 30 days.
AI and your content
- Grounding
- AI answers are generated only from your own published articles in that workspace.
- Training
- Your content is not used to train shared or third-party models.
- Retention
- AI prompts and responses are retained for troubleshooting for 30 days, then deleted. Retention can be reduced on Enterprise.
- Opt out
- AI features can be disabled per workspace or per project if your policy does not permit them.
Auditing and monitoring
- Content audit
- Every create, edit, publish, unpublish, approve and delete is logged with actor, timestamp and previous value.
- Access audit
- Sign-ins, permission changes and API key usage are logged.
- Retention
- Ninety days on Growth, unlimited on Business and Enterprise, exportable via API.
- Alerting
- Availability, error rate and latency monitored continuously with on-call escalation.
Organisational controls
- Least privilege
- Production access is limited to named engineers, granted on request, logged, and reviewed quarterly.
- Change management
- Peer-reviewed changes, automated tests, and staged rollout with the ability to roll back.
- Vendors
- Sub-processors are documented and reviewed. The current list is available on request and in the DPA.
- People
- Background checks on hire, confidentiality agreements, and annual security training.
Where we are, and where we are not
Claiming a certification you do not hold is the fastest way to fail a procurement review. Here is the current position.
GDPR alignment
A data processing agreement covering controller and processor obligations, sub-processor disclosure, and EU data residency, is available on request.
Data residency
India, EU and US regions are live today. Residency can be committed contractually on Enterprise.
SOC 2 Type II
Controls are implemented and an observation window is under way. Ask sales for the current status and expected report date.
ISO/IEC 27001
Scoping complete; certification audit planned. We will not claim it before the certificate is issued.
Reporting a vulnerability
Email security@thedocs.in with reproduction steps. We acknowledge within two working days, keep you updated while we fix it, and credit researchers who ask to be named. Please do not test against another customer's workspace.
Questions people ask before they start
Need the full security pack?
We will send the architecture summary, sub-processor list, DPA and a completed standard questionnaire - usually the same working day.
Questions first? Email sales@thedocs.in or call +91 8585953085.