Security
Every document session runs through encrypted channels, verified identities, and tamper-evident records. The controls your clients and compliance teams expect are on by default — no add-ons required.
Controls
Client interview answers are encrypted at rest using AES-256-GCM authenticated encryption on all paid plans. Sensitive fields — SSNs, dates of birth, financial data — are never stored in plaintext.
Learn more →
Every session generates a complete audit record: session creation, OTP verification, signature event, and submission — each with a precise timestamp, IP address, and device fingerprint. Stored independently of the PDF.
Learn more →
Every signed document receives a trusted timestamp from an independent TSA authority — cryptographic proof of exactly when it was signed that cannot be altered after the fact.
Learn more →
A SHA-256 hash of every completed PDF is recorded at generation time and stored in the audit trail. Any modification to the file after signing produces a hash mismatch — detectable on verification.
Learn more →
Restrict access to your Docuplete organisation to specific IP addresses or CIDR ranges. Enforce access from your office network or VPN — block all other traffic by default.
Learn more →
Automate user lifecycle management through your identity provider. Users provisioned and deprovisioned automatically — no manual seat management for enterprise teams.
Learn more →
Identity verification
Docuplete uses OTP verification to confirm the signer's identity via their email address before accepting a signature — producing a legally defensible audit trail on every submission.
Each document session has its own tokenised URL. The link is single-use — opening it on a different device does not start a separate session.
Before the client can sign, Docuplete sends a one-time code to their email address. They enter it to confirm they control the inbox.
The verified signature event — with timestamp, IP, device, and OTP confirmation — is written to the immutable audit trail and appended to the PDF as a signing certificate page.
In transit
All data between clients, Docuplete's servers, and your integrations is transmitted over TLS. Combined with AES-256-GCM at rest, client data is protected through its entire lifecycle.
Every query is scoped to your organisation. Data from other Docuplete customers is inaccessible by design — enforced at the database and API middleware level.
Docuplete's security architecture — encryption, audit trails, access controls, and tenant isolation — is built around SOC 2 Trust Services Criteria. SOC 2 Type II audit in progress.
Compliance by industry
Different industries have different obligations. Here is how Docuplete's built-in security controls address the requirements most commonly raised by compliance teams in financial services, healthcare, and legal.
| Docuplete control | FINRA / SEC (financial services) | HIPAA (healthcare) | Legal / E-sign law |
|---|---|---|---|
| AES-256-GCM encryption at rest | Supports data protection requirements for customer records under SEC Rule 17a-4 | Addresses HIPAA encryption-at-rest implementation specification for ePHI | Protects signed document integrity from unauthorized access |
| OTP identity verification | Supports suitability documentation by confirming signer identity before acceptance | Supports authentication controls for individuals accessing ePHI | Satisfies "intent to sign" and identity attribution under ESIGN and UETA |
| RFC 3161 trusted timestamps | Provides tamper-proof record of when documents were signed for recordkeeping audits | Timestamps the exact moment ePHI-containing documents were signed | Creates an independent, verifiable record of signing time that withstands legal challenge |
| SHA-256 tamper detection | Detects post-submission alteration of client documents — critical for disputes | Ensures integrity of ePHI-containing records after generation | Provides hash-based proof that the signed document has not been altered |
| Full audit trail (IP, device, timestamp) | Satisfies recordkeeping and supervision audit requirements | Addresses HIPAA audit control implementation specification | Provides the evidence chain required for e-sign enforceability |
This table is informational, not legal advice. Confirm compliance obligations with your legal or compliance team.
Data retention and deletion
Docuplete gives you control over how long submission data is retained and what happens to it when you leave.
Completed PDF submissions and their associated answer data are stored in your Docuplete submission bank for the duration of your subscription. You can download any submission at any time. Enterprise plans can configure custom retention periods aligned to their internal data lifecycle policies.
Audit trails — the per-session records of OTP events, signature timestamps, IP addresses, and device fingerprints — are retained separately from the PDF. They are preserved for the life of your account and are available for export. Even if a submission is deleted, the audit record remains until explicitly removed.
When you close your Docuplete account, you receive a data export of all submission records, audit trails, and field-answer data in a standard format. Data is permanently deleted from Docuplete's systems within 30 days of account closure. No data is sold to third parties at any point.
Docuplete supports deletion of individual submission records on request — including the associated answer data and PDF — while preserving the audit trail record as required for legal defensibility. Enterprise customers can manage erasure requests through the API. Contact [email protected] for individual deletion requests.
Frequently asked questions
Docuplete's application and database infrastructure runs on Railway, which uses AWS data centers in the United States. File storage (completed PDFs) uses Cloudflare R2, also US-region. All data is stored within the United States. If your compliance requirements mandate a specific region or a dedicated infrastructure arrangement, contact us to discuss Enterprise options.
Docuplete implements many of the technical safeguards required under HIPAA — AES-256 encryption at rest, TLS in transit, access controls, and audit logging. However, HIPAA compliance also requires a signed Business Associate Agreement (BAA). Docuplete offers BAAs to Enterprise customers. If you intend to collect Protected Health Information (ePHI) through Docuplete forms, contact us before deploying to confirm your setup and execute the required BAA.
Yes, for the vast majority of use cases in the United States. Docuplete's e-signatures satisfy the requirements of the federal ESIGN Act and the Uniform Electronic Transactions Act (UETA): the signer demonstrates intent to sign, identity is confirmed via email OTP, and a tamper-evident record is preserved. The RFC 3161 trusted timestamp provides additional legal weight. Certain documents — wills, certain real estate transfers, court filings — are excluded from ESIGN and require wet signatures; Docuplete is not designed for those.
Docuplete's SOC 2 Type II audit is in progress. A SOC 2 Type I report is available to Enterprise customers under NDA. For security questionnaire responses and vendor security review support, contact [email protected] — we respond to questionnaires for Enterprise prospects and customers.
Each OTP is single-use and expires after a short window (typically 10 minutes). If a fraudulent OTP entry is detected — for example, a session opened from an unusual IP within the OTP window — the event is captured in the audit trail with the full IP and device fingerprint. The audit trail records both the legitimate and any anomalous access attempts, giving you a complete picture for dispute resolution. IP allowlisting (Enterprise) can further restrict who can access the interview flow at the network level.
If you discover a potential security vulnerability in Docuplete, please email [email protected] with a description of the issue, steps to reproduce, and your contact information. We aim to acknowledge reports within 24 hours and provide a resolution timeline within 72 hours for verified critical issues. Please do not publicly disclose a vulnerability before it has been addressed. We do not currently operate a formal bug bounty program, but we recognize responsible disclosures.
We're happy to walk through Docuplete's controls with your security or compliance team.
Contact usRelated