Doconio
ENDE
Start free trial

Security and trust

Security measures buyers can understand.

Doconio protects customer data through controlled access, private storage, encryption and recovery measures. Review the documented measures, contractual information and disclosed service providers here.

Request a product conversationReview legal documents

Security overview

Transparent

Customer data

Germany West Central

Transport

TLS 1.2+

Tenant-scoped authorization


Private document storage


Traceable changes

Assessment basis

Data location
Access controls
Recovery

Hosting and data location

Customer data and documents are processed in Azure Germany West Central. Productive customer operations are separated from development and testing, so customer data remains in the intended environment.

Tenant and access controls

Access is limited to the relevant customer environment and the permissions of the signed-in user. Roles and capabilities determine which records and functions are available. Enterprise customers can connect Microsoft Entra ID and use dedicated service accounts for approved integrations.

Encryption and operations

HTTPS with TLS 1.2 or higher protects data in transit, while Azure services encrypt stored data. Customer document storage is private and production credentials are protected in Azure Key Vault. Monitoring and operational alerts help us identify and investigate technical issues.

Process

What you can review and align

Technical measures: Azure Germany West Central, tenant and role controls, TLS 1.2+, encryption at rest, private document storage, Key Vault and monitoring.

Public documents: subprocessors, international data access, switching and data-export information.

Contracting documents: DPA, technical and organizational measures and agreed retention, recovery, support and incident requirements.

Recovery safeguards: earlier database restore points, document versioning and protection against accidental deletion.

Current limits: no ISO 27001, SOC 2 or TISAX certification; WORM archival storage and customer-managed keys are not standard features.

Learn more

Documents and contact paths for your security review

Legal and privacy overview

Questions and answers

Security and data protection FAQ

Is a DPA available?

Yes. A Data Processing Agreement under Art. 28 GDPR, the technical and organizational measures and the applicable subprocessor list are provided during the contracting process.

How does Doconio handle AI processing?

AI processing is optional and is not part of standard data processing. It is enabled only as part of an explicitly agreed customer scope, with transparent information about the service, data categories, processing region and applicable privacy documents.

Can customer data be restored?

Yes. Database and document storage are protected by several recovery safeguards, including earlier restore points, versioning and protection against accidental deletion. We align detailed retention periods and binding recovery requirements with you during the security or contracting process.

How does Doconio provide traceability?

Doconio versions documents and records important changes and access activity. This keeps responsibilities and relevant actions connected to the evidence workflow and supports operational and audit traceability.

How does Doconio handle external service providers?

We keep the set of service providers focused and disclose who processes which data and for what purpose. Providers are contractually integrated into our data-protection framework, and relevant changes follow the process agreed in the DPA.

Does Doconio have independent provider certifications?

Doconio does not currently hold an independent provider certification such as ISO 27001, SOC 2 or TISAX. For security reviews, we provide documented technical and organizational measures, contractual information and details about the subprocessors we use.

Next step

Clarify security requirements early.

In a product conversation, we align your evidence workflow with data location, access model, Enterprise connections and the contractual documents your review requires.

What happens after your request

  • You receive a personal reply from the Doconio team by email.
  • In the first conversation, we look at your current evidence process and the teams involved.
  • You then receive a recommendation for a useful starting point, package, implementation path and any required integrations.
What would you like to discuss?
Company size (optional)
Current trigger (optional)

Information about how we process your details is available in our privacy policy.

Doconio

Evidence. Trust. Assurance.

info@doconio.com+49 (0)30 2578 5767Doconio on LinkedIn

Product

ProductEvidence managementSupplier complianceConformity HubPolicy managementContract evidenceTrust CenterCertifications

© 2026 Doconio.