Security

Security built in,
not bolted on.

Every document session runs through encrypted channels, verified identities, and tamper-evident records. The controls your clients and compliance teams expect are on by default — no add-ons required.

Controls

What protects every document session.

Identity verification

Every signer is verified before signing.

Docuplete uses OTP verification to confirm the signer's identity via their email address before accepting a signature — producing a legally defensible audit trail on every submission.

1

Client receives a unique link

Each document session has its own tokenised URL. The link is single-use — opening it on a different device does not start a separate session.

2

OTP sent to their email

Before the client can sign, Docuplete sends a one-time code to their email address. They enter it to confirm they control the inbox.

3

Signature accepted, audit trail sealed

The verified signature event — with timestamp, IP, device, and OTP confirmation — is written to the immutable audit trail and appended to the PDF as a signing certificate page.

In transit

End-to-end protection for every document.

TLS in transit

All data between clients, Docuplete's servers, and your integrations is transmitted over TLS. Combined with AES-256-GCM at rest, client data is protected through its entire lifecycle.

Multi-tenant isolation

Every query is scoped to your organisation. Data from other Docuplete customers is inaccessible by design — enforced at the database and API middleware level.

SOC 2-aligned controls

Docuplete's security architecture — encryption, audit trails, access controls, and tenant isolation — is built around SOC 2 Trust Services Criteria. SOC 2 Type II audit in progress.

Compliance by industry

How Docuplete's controls map to your regulatory requirements.

Different industries have different obligations. Here is how Docuplete's built-in security controls address the requirements most commonly raised by compliance teams in financial services, healthcare, and legal.

Docuplete control FINRA / SEC (financial services) HIPAA (healthcare) Legal / E-sign law
AES-256-GCM encryption at rest Supports data protection requirements for customer records under SEC Rule 17a-4 Addresses HIPAA encryption-at-rest implementation specification for ePHI Protects signed document integrity from unauthorized access
OTP identity verification Supports suitability documentation by confirming signer identity before acceptance Supports authentication controls for individuals accessing ePHI Satisfies "intent to sign" and identity attribution under ESIGN and UETA
RFC 3161 trusted timestamps Provides tamper-proof record of when documents were signed for recordkeeping audits Timestamps the exact moment ePHI-containing documents were signed Creates an independent, verifiable record of signing time that withstands legal challenge
SHA-256 tamper detection Detects post-submission alteration of client documents — critical for disputes Ensures integrity of ePHI-containing records after generation Provides hash-based proof that the signed document has not been altered
Full audit trail (IP, device, timestamp) Satisfies recordkeeping and supervision audit requirements Addresses HIPAA audit control implementation specification Provides the evidence chain required for e-sign enforceability

This table is informational, not legal advice. Confirm compliance obligations with your legal or compliance team.

Data retention and deletion

Your data, your control.

Docuplete gives you control over how long submission data is retained and what happens to it when you leave.

Submission data retention

Completed PDF submissions and their associated answer data are stored in your Docuplete submission bank for the duration of your subscription. You can download any submission at any time. Enterprise plans can configure custom retention periods aligned to their internal data lifecycle policies.

Audit trail retention

Audit trails — the per-session records of OTP events, signature timestamps, IP addresses, and device fingerprints — are retained separately from the PDF. They are preserved for the life of your account and are available for export. Even if a submission is deleted, the audit record remains until explicitly removed.

Account deletion and data export

When you close your Docuplete account, you receive a data export of all submission records, audit trails, and field-answer data in a standard format. Data is permanently deleted from Docuplete's systems within 30 days of account closure. No data is sold to third parties at any point.

Right to erasure (GDPR / CCPA)

Docuplete supports deletion of individual submission records on request — including the associated answer data and PDF — while preserving the audit trail record as required for legal defensibility. Enterprise customers can manage erasure requests through the API. Contact [email protected] for individual deletion requests.

Frequently asked questions

Security questions, answered.

Where is Docuplete's infrastructure hosted?

Docuplete's application and database infrastructure runs on Railway, which uses AWS data centers in the United States. File storage (completed PDFs) uses Cloudflare R2, also US-region. All data is stored within the United States. If your compliance requirements mandate a specific region or a dedicated infrastructure arrangement, contact us to discuss Enterprise options.

Is Docuplete HIPAA-compliant? Can I use it for patient intake forms?

Docuplete implements many of the technical safeguards required under HIPAA — AES-256 encryption at rest, TLS in transit, access controls, and audit logging. However, HIPAA compliance also requires a signed Business Associate Agreement (BAA). Docuplete offers BAAs to Enterprise customers. If you intend to collect Protected Health Information (ePHI) through Docuplete forms, contact us before deploying to confirm your setup and execute the required BAA.

Are Docuplete's e-signatures legally binding?

Yes, for the vast majority of use cases in the United States. Docuplete's e-signatures satisfy the requirements of the federal ESIGN Act and the Uniform Electronic Transactions Act (UETA): the signer demonstrates intent to sign, identity is confirmed via email OTP, and a tamper-evident record is preserved. The RFC 3161 trusted timestamp provides additional legal weight. Certain documents — wills, certain real estate transfers, court filings — are excluded from ESIGN and require wet signatures; Docuplete is not designed for those.

Can Docuplete issue a security questionnaire response or SOC 2 report?

Docuplete's SOC 2 Type II audit is in progress. A SOC 2 Type I report is available to Enterprise customers under NDA. For security questionnaire responses and vendor security review support, contact [email protected] — we respond to questionnaires for Enterprise prospects and customers.

What happens if a client's email is compromised and someone intercepts the OTP?

Each OTP is single-use and expires after a short window (typically 10 minutes). If a fraudulent OTP entry is detected — for example, a session opened from an unusual IP within the OTP window — the event is captured in the audit trail with the full IP and device fingerprint. The audit trail records both the legitimate and any anomalous access attempts, giving you a complete picture for dispute resolution. IP allowlisting (Enterprise) can further restrict who can access the interview flow at the network level.

How do I report a security vulnerability?

If you discover a potential security vulnerability in Docuplete, please email [email protected] with a description of the issue, steps to reproduce, and your contact information. We aim to acknowledge reports within 24 hours and provide a resolution timeline within 72 hours for verified critical issues. Please do not publicly disclose a vulnerability before it has been addressed. We do not currently operate a formal bug bounty program, but we recognize responsible disclosures.

Security questions?
Talk to us.

We're happy to walk through Docuplete's controls with your security or compliance team.

Contact us

Related

Security features in detail