Security and trust
Security buyers can verify.
Doconio protects customer data through controlled access, private document storage, encryption, traceable activity and documented recovery measures. You receive a clear basis for assessing security and data protection before the first productive workflow.
Security overview
Customer data
Germany West Central
Transport
TLS 1.2+
Tenant-scoped authorization
Private document storage
Traceable changes
Assessment basis
Hosting and data location
Customer data and documents are processed in Azure Germany West Central. Productive customer operations are separated from development and testing, so customer data remains in the intended environment.
Tenant and access controls
Access is limited to the relevant customer environment and the permissions of the signed-in user. Roles and capabilities determine which records and functions are available. Enterprise customers can connect Microsoft Entra ID and use dedicated service accounts for approved integrations.
Encryption and operations
HTTPS with TLS 1.2 or higher protects data in transit, while Azure services encrypt stored data. Customer document storage is private and production credentials are protected in Azure Key Vault. Monitoring and operational alerts help us identify and investigate technical issues.
Process
What customers receive
Customer data and documents are processed in Azure Germany West Central, with productive operations separated from development and testing.
Roles, capabilities and tenant boundaries limit access; Enterprise customers can connect Microsoft Entra ID.
TLS 1.2+, Azure encryption at rest, private document storage and Azure Key Vault protect data and credentials.
Document versions and recorded changes support traceable evidence workflows.
Configured database and document-storage recovery measures support operational restoration.
Learn more
Public security and privacy documents
Questions and answers
Security and data protection FAQ
Is a DPA available?
Yes. A Data Processing Agreement under Art. 28 GDPR, the technical and organizational measures and the applicable subprocessor list are provided during the contracting process.
How does Doconio handle AI processing?
AI processing is optional and is not part of standard data processing. It is enabled only as part of an explicitly agreed customer scope, with transparent information about the service, data categories, processing region and applicable privacy documents.
Can customer data be restored?
Yes. Database and document storage are protected by several recovery safeguards, including earlier restore points, versioning and protection against accidental deletion. We align detailed retention periods and binding recovery requirements with you during the security or contracting process.
How does Doconio provide traceability?
Doconio versions documents and records important changes and access activity. This keeps responsibilities and relevant actions connected to the evidence workflow and supports operational and audit traceability.
How does Doconio handle external service providers?
We keep the set of service providers focused and disclose who processes which data and for what purpose. Providers are contractually integrated into our data-protection framework, and relevant changes follow the process agreed in the DPA.
How can I report a vulnerability?
Send a confidential report to security@doconio.com or use the published security.txt contact. Our disclosure policy explains how we receive, assess and respond to reports.
Next step
Clarify security requirements early.
In a product conversation, we align your evidence workflow with data location, access model, Enterprise connections and the contractual documents your review requires.