Doconio
ENDE
Product conversation

Security and trust

Security buyers can verify.

Doconio protects customer data through controlled access, private document storage, encryption, traceable activity and documented recovery measures. You receive a clear basis for assessing security and data protection before the first productive workflow.

Request a product conversationReview legal documents

Security overview

Transparent

Customer data

Germany West Central

Transport

TLS 1.2+

Tenant-scoped authorization


Private document storage


Traceable changes

Assessment basis

Data location
Access controls
Recovery

Hosting and data location

Customer data and documents are processed in Azure Germany West Central. Productive customer operations are separated from development and testing, so customer data remains in the intended environment.

Tenant and access controls

Access is limited to the relevant customer environment and the permissions of the signed-in user. Roles and capabilities determine which records and functions are available. Enterprise customers can connect Microsoft Entra ID and use dedicated service accounts for approved integrations.

Encryption and operations

HTTPS with TLS 1.2 or higher protects data in transit, while Azure services encrypt stored data. Customer document storage is private and production credentials are protected in Azure Key Vault. Monitoring and operational alerts help us identify and investigate technical issues.

Process

What customers receive

Customer data and documents are processed in Azure Germany West Central, with productive operations separated from development and testing.

Roles, capabilities and tenant boundaries limit access; Enterprise customers can connect Microsoft Entra ID.

TLS 1.2+, Azure encryption at rest, private document storage and Azure Key Vault protect data and credentials.

Document versions and recorded changes support traceable evidence workflows.

Configured database and document-storage recovery measures support operational restoration.

Learn more

Public security and privacy documents

Legal and privacy overview

Questions and answers

Security and data protection FAQ

Is a DPA available?

Yes. A Data Processing Agreement under Art. 28 GDPR, the technical and organizational measures and the applicable subprocessor list are provided during the contracting process.

How does Doconio handle AI processing?

AI processing is optional and is not part of standard data processing. It is enabled only as part of an explicitly agreed customer scope, with transparent information about the service, data categories, processing region and applicable privacy documents.

Can customer data be restored?

Yes. Database and document storage are protected by several recovery safeguards, including earlier restore points, versioning and protection against accidental deletion. We align detailed retention periods and binding recovery requirements with you during the security or contracting process.

How does Doconio provide traceability?

Doconio versions documents and records important changes and access activity. This keeps responsibilities and relevant actions connected to the evidence workflow and supports operational and audit traceability.

How does Doconio handle external service providers?

We keep the set of service providers focused and disclose who processes which data and for what purpose. Providers are contractually integrated into our data-protection framework, and relevant changes follow the process agreed in the DPA.

How can I report a vulnerability?

Send a confidential report to security@doconio.com or use the published security.txt contact. Our disclosure policy explains how we receive, assess and respond to reports.

Next step

Clarify security requirements early.

In a product conversation, we align your evidence workflow with data location, access model, Enterprise connections and the contractual documents your review requires.

What happens after your request

  • You receive a personal reply from the Doconio team by email.
  • In the first conversation, we look at your current evidence process and the teams involved.
  • You then receive a recommendation for a useful starting point, package, implementation path and any required integrations.
What would you like to discuss?
Company size (optional)
Current trigger (optional)

Information about how we process your details is available in our privacy policy.