Skip to main content
Security & compliance

What your security team will want to know

Written to answer a vendor questionnaire rather than to reassure in the abstract. If something you need is missing, ask and we will answer specifically.

How does TheDocs secure customer content?

TheDocs encrypts data in transit with TLS 1.2 or higher and at rest with AES-256, isolates each customer workspace logically, enforces role-based access control with optional SAML or OIDC single sign-on, records every content and permission change in an audit log, and lets customers choose whether their data lives in India, the European Union or the United States.

  • TLS 1.2+ in transit, AES-256 at rest.
  • Per-workspace logical isolation, enforced at the data layer.
  • SAML 2.0 and OIDC SSO; SCIM provisioning on Enterprise.
  • Point-in-time recovery within a 30-day window.
  • Least-privilege internal access, reviewed quarterly.
  • Customer content is never used to train shared models.

Encryption and network

In transit
TLS 1.2 or higher on every endpoint, including custom domains. HSTS is enabled and HTTP is redirected.
At rest
AES-256 on databases, object storage and backups.
Certificates
Custom-domain certificates are issued and renewed automatically; you never handle a private key.
Secrets
Application secrets live in a managed vault, rotated on a schedule and never in source control.

Access control

Roles
Owner, admin, author, reviewer and reader, assignable per project and per category.
Single sign-on
SAML 2.0 and OIDC from the Growth plan. Enforce SSO-only sign-in to disable password login entirely.
Provisioning
SCIM 2.0 on Enterprise, so leavers lose access when HR deactivates them, not when someone remembers.
Reader access
Public, sign-in required, IP-restricted, or limited to named partner accounts - configured per project.

Data handling and residency

Residency
Choose India, the European Union or the United States when the workspace is created. Content and backups stay in the chosen region.
Isolation
Every workspace is logically isolated. Queries are scoped at the data layer, not only in application code.
Backups
Continuous backup with point-in-time recovery inside a 30-day window. Restores are tested quarterly.
Deletion
On cancellation, content is retained for 30 days for export, then deleted from primary storage and purged from backups within a further 30 days.

AI and your content

Grounding
AI answers are generated only from your own published articles in that workspace.
Training
Your content is not used to train shared or third-party models.
Retention
AI prompts and responses are retained for troubleshooting for 30 days, then deleted. Retention can be reduced on Enterprise.
Opt out
AI features can be disabled per workspace or per project if your policy does not permit them.

Auditing and monitoring

Content audit
Every create, edit, publish, unpublish, approve and delete is logged with actor, timestamp and previous value.
Access audit
Sign-ins, permission changes and API key usage are logged.
Retention
Ninety days on Growth, unlimited on Business and Enterprise, exportable via API.
Alerting
Availability, error rate and latency monitored continuously with on-call escalation.

Organisational controls

Least privilege
Production access is limited to named engineers, granted on request, logged, and reviewed quarterly.
Change management
Peer-reviewed changes, automated tests, and staged rollout with the ability to roll back.
Vendors
Sub-processors are documented and reviewed. The current list is available on request and in the DPA.
People
Background checks on hire, confidentiality agreements, and annual security training.
Certifications

Where we are, and where we are not

Claiming a certification you do not hold is the fastest way to fail a procurement review. Here is the current position.

In place

GDPR alignment

A data processing agreement covering controller and processor obligations, sub-processor disclosure, and EU data residency, is available on request.

In place

Data residency

India, EU and US regions are live today. Residency can be committed contractually on Enterprise.

In progress

SOC 2 Type II

Controls are implemented and an observation window is under way. Ask sales for the current status and expected report date.

In progress

ISO/IEC 27001

Scoping complete; certification audit planned. We will not claim it before the certificate is issued.

Reporting a vulnerability

Email security@thedocs.in with reproduction steps. We acknowledge within two working days, keep you updated while we fix it, and credit researchers who ask to be named. Please do not test against another customer's workspace.

Frequently asked

Questions people ask before they start

Not yet. Controls are implemented and an observation window is under way, and we will not claim the certification before the report is issued. Ask sales for the current status and the expected report date, and we will put it in writing.

India, the European Union or the United States. You choose the region when the workspace is created; content and backups stay in that region. Enterprise contracts can pin residency.

No. Content is used to retrieve and ground answers within your own workspace. It is not used to train shared or third-party models, and it is never exposed to another customer.

Yes, per workspace or per project. Some regulated customers disable AI on internal SOP projects while leaving it on for the public help centre.

Email security@thedocs.in with reproduction steps. We acknowledge within two working days, keep you updated through the fix, and credit researchers who want to be named.

It is retained for 30 days so you can export it, then deleted from primary storage and purged from backups within a further 30 days.

Need the full security pack?

We will send the architecture summary, sub-processor list, DPA and a completed standard questionnaire - usually the same working day.

Questions first? Email sales@thedocs.in or call +91 8585953085.