Security
What you can check, and what we will not claim.
The full posture behind the four facts on the homepage, written so a questionnaire can cite a URL instead of a screenshot.
01
The sealed file, described exactly.
One cryptographic signature is applied over the exact bytes the sender approved. A later change to any byte breaks it, and a PDF reader checks that offline, with no account and with nothing of ours in the path.
The signature is a detached CAdES signature covering the whole file, applied in-process at the moment the document is sealed. The signing identity is held as a function environment secret, which is a deliberate key-custody decision for this version rather than an oversight: there is no cloud key-management service and no managed certificate authority behind it yet.
What that means for a reader opening the file: the signature validates as covering the document, and the issuer will not be reported as trusted, because the identity is our own rather than a member of a reader's trust list. We do not embed certificate chains, revocation responses or a timestamp token, so we make no long-term-validation claim and no claim about what the file will report in ten years.
Before anything is sealed, the rendered text is compared against the canonical text it was rendered from, and a font-coverage check refuses the seal on any missing glyph. A document that fails either produces no artifact at all rather than a signed one with a hole in it.
Validated by an independent implementation in CI — the library that seals is never the library that verifies
02
The record is append-only and chained.
Every event hashes the previous entry's digest, so a removed or altered step is detectable rather than deniable.
The ledger is written through a single bounded database function that computes each entry over the previous head. There is no update path and no delete path for a tenant, and the chain is what makes a missing step visible instead of invisible.
Stated as plainly: the chain head is not yet anchored to an external timestamp authority on a schedule. Anchoring exists as an operator-run command, nothing schedules it, and the signing path contacts no timestamp authority. A control nobody runs on a cadence is an intention, so we describe it as one.
The ledger never enters a logging or analytics vendor, and neither does document content or party personal data. No observability vendor is connected to any surface today.
03
Where your documents live.
A single United States region, private object storage, and no immutability claim we cannot support.
Every browser-facing surface is served over HTTPS only. The domain is submitted to the HSTS preload list, so a browser refuses a plain-HTTP connection to it before a request is made rather than after a redirect. Document bytes are held in private object storage that no browser can reach without a scoped, expiring grant, and they pass through the application process only while a file is being prepared, flattened or sealed.
Evidentiary writes are tenant-prefixed, content-addressed and refuse to overwrite. That means a duplicate finalize converges on one artifact and a replacement is detectable — but it is not administrator-proof immutability, and we make no WORM or Object Lock claim in this version.
An organisation's region is fixed when it is created and cannot be changed afterwards. EU and UK residency are not offered. Retention and deletion, including the one category that survives an erasure request and why, are set out in the privacy notice rather than summarised here, because a summary is the copy that goes stale.
Privacy notice, sections 5 and 7 — published, indexable, no account required
04
What a model sees, and what it can never touch.
Every model request requires zero-data-retention routing and prompt-training opt-out.
That sentence describes the control set on every model call the application makes: requests are routed through a gateway with zero-data-retention required and routing restricted to a single named provider. It does not assert that every subprocessor agreement and addendum this arrangement needs has been executed and filed, and we will not imply otherwise.
Separately, and more importantly for the artifact: nothing a model produces can reach the bytes that get signed. Proposals, summaries, answers and citations live in a sidecar layer. The bytes that are flattened, hashed and sealed are exactly the file a human approved, and the server re-measures the stored document before accepting where anything is placed on it. A suggestion that no human confirmed is refused at the send path, not filtered out of a report afterwards.
The assistant identifies itself as software on every signer surface, it answers only from the frozen text of the document in front of the reader, and an answer with no matched geometry is not shown as a citation. It quotes and cites. It does not advise, and it escalates to the sender rather than guessing.
05
One tenant cannot reach another.
Row-level security is the floor, not the mechanism.
Every tenant table has row-level security enabled and forced, including for the table's owner. The administrative database role that bypasses those policies holds no table privilege at all, so a query that tries to read a tenant table directly with it fails outright rather than succeeding quietly for every tenant. Application code reaches tenant data only through bounded functions that take the organisation as an argument, and each one treats zero affected rows as a failure rather than as success.
The operator of the platform is not a data gate. Our own console can see aggregate counts and nothing else — it cannot select tenant identifiers, personal data, document content, hashes, IP addresses or user agents. A support request that genuinely needs a customer's data goes through a consent-bounded flow with the customer's agreement, or it does not happen.
Every route that serves document bytes, party names or a hash is excluded from search indexing in four independent layers, and the exclusion list is declared once so the layers cannot disagree about it.
06
What we do not have yet.
This section is here because you would find it anyway, and finding it here is worth more to both of us.
No SOC 2 report. The observation window has not opened and there is no date for it.
No ISO 27001, and no HITRUST.
No HIPAA posture and no business associate agreement. Protected health information should not be sent through OctoDoc.
No EU or UK data residency. One United States region, fixed at account creation.
No third-party accessibility conformance report, and none booked. The target when one is commissioned is WCAG 2.2 AA on the signing path.
No penetration test, and no bound insurance.
No single sign-on, no SCIM provisioning and no role-based administration beyond the account owner.
No signer identity step-up: no access code on a signing link, and no government-identity or biometric check.
No AATL-member certificate, no archival signature profile, and no long-term validation.
07
Who else touches your document.
The register below is the one we maintain — the same list the privacy notice and the data processing agreement render, from a single source.
Vercel (including AI Gateway)
Application hosting, document processing and transport for model calls
US · Document content: Yes — while preparing, flattening or sealing, and as bounded model context under required zero-data-retention routing
Supabase
Postgres, authentication and private object storage
US, us-west-2 · Document content: Yes — including page bytes in private Storage
Cloudflare
Authoritative DNS and inbound email routing for the OctoDoc domain
US · Document content: No
Resend
Account email, signature requests, reminders, sealed-copy delivery and the early-access mailing list
US · Document content: Document names and email content, never page bytes
Stripe
Subscription billing
US · Document content: No
Anthropic
Document authoring, edit proposals, classification and cited questions
US · Document content: Yes — bounded document content routed by the Gateway under required zero-data-retention and prompt-training opt-out controls
At least 30 days’ notice is given before a subprocessor is added or replaced, and a customer may object and terminate the affected subscription for a prorated refund if we proceed. The full table, including providers named for capabilities that do not exist yet and are marked as such, is in the privacy notice and the data processing agreement.
08
Asking us something this page does not answer.
Send the question rather than the questionnaire, if you can — a specific question gets a specific answer faster.
Privacy and security questions go to privacy@octodoc.org. If your process requires a filled-in vendor questionnaire, say so and we will complete it, including the rows where the answer is no.
OctoDoc is unrelated to other businesses using the word octodoc, including a commercial printer and an unrelated consumer AI application. The operating entity and its registration will be published with the trust centre when both exist.