Security and trust

Security built for financial and health data

Docsumo is SOC 2 Type 2 audited, ISO/IEC 27001:2022 certified, and HIPAA and GDPR compliant. This page shows how we handle your documents, who can see them, where they are stored, which AI models touch them and how long we keep them.

Last reviewed September 25, 2026

In short

Docsumo is an intelligent document processing (IDP) platform. It runs as a hosted service on Amazon Web Services and Google Cloud, holds SOC 2 Type 2 and ISO/IEC 27001:2022, encrypts data in transit (TLS) and at rest (AES-256), and gives you role-based access, single sign-on, enforced MFA and an activity log of every action in your account.

Compliance

Audited, not self-declared.

Lending, insurance, healthcare and eligibility teams send Docsumo bank statements, tax returns, ACORD forms and Medicaid applications. These programs cover that work.

  • SOC 2 Type 2

    Audited

    An independent CPA firm audits Docsumo's controls every year. A Type 2 audit tests that controls operated effectively across a full audit period, not only that they were designed well on one day.

    Docsumo received its first SOC 2 report in 2021. The controls behind the audit are listed further down this page.

    SOC 2 Type 2 report: shared case by case. Request it in the trust center or ask your account team.

  • ISO/IEC 27001:2022

    Certified

    Docsumo's information security management system is certified to ISO/IEC 27001:2022 by Ameri-Co Quality Standards Registech (certificate AMER30761). Docsumo was first certified in July 2023; the current certificate was issued in August 2026, with yearly surveillance audits.

    Scope: design, development, maintenance, technical support, sales and marketing of the Docsumo platform.

    ISO 27001 certificate: request access in the trust center or ask your account team.

  • HIPAA

    Compliant

    Docsumo is HIPAA compliant for protected health information. Eligibility and revenue-cycle teams use it for Medicaid applications and the bank statements, pay stubs and IDs inside them.

    Docsumo signs a Business Associate Agreement (BAA) with customers who process protected health information. Under its PHI Breach Notification Policy, a breach involving health data is reported to the customer in writing without unreasonable delay.

    BAA: available, ask your account team. HIPAA policies: request access in the trust center.

  • GDPR

    Compliant

    For the documents you upload and the data extracted from them, Docsumo is the data processor. For account data such as names, emails and billing details, Docsumo is the controller.

    Docsumo appoints a privacy officer, runs data protection impact assessments, checks consent before processing personal data and follows set procedures for moving it across regions. Data can stay in the EU (Frankfurt) or the UK (London).

    DPA: available, ask your account team. Access, correction or deletion requests: privacy@docsumo.com, completed within 30 days. Full terms in the Privacy Policy.

Encryption at rest
AES-256
Encryption in transit
HTTPS with TLS
Penetration testing
External, every year
ISO 27001 certified
Since July 2023
AI and your data

Which models read your documents.

Your documents are processed to return your data. Here is the path a document takes, which outside providers are involved and what you can switch on or off.

  1. Your documentUpload, email, API, or Google Drive, SharePoint and S3.
  2. Docsumo on AWS and Google CloudEncrypted in transit and at rest.
  3. Model waterfallLarge language models via API. When one is unsure of a field, the next checks it.
  4. Your reviewersFields below your threshold go to the review queue.
  5. Your systemsData goes only where you send it.
AI model APIs used in the waterfallAnthropic, PBC (USA, EU)OpenAI OpCo, LLC (USA, EU)Both are listed on our public subprocessor list, with AWS and Google Cloud for hosting and AI services.
No shared or third-party model training
Docsumo reads your documents with large language models called through APIs. Your documents and extracted data are not used to train shared or third-party models.
Bound like every subprocessor
Docsumo carries out due diligence before engaging any subprocessor, including the AI model providers. Each is bound by confidentiality agreements and data protection terms consistent with GDPR.
Governed by written AI policies
An Artificial Intelligence Usage Policy and an Artificial Intelligence Data Security Policy set how AI is used at Docsumo and how data sent to models is protected. Both are in the trust center.
Your data is never sold
Docsumo does not sell your personal data or document data under any circumstances.
Controls in your account
The AI Extractor is set per document type: choose Basic, Standard or Advanced, or switch it off. Continuous Learning, which uses your reviewers' corrections to improve suggestions on similar documents, is also on or off per document type, and applies only to your account.
Your own AI agents
If you connect Claude, Cursor or an app built on the OpenAI API through the Docsumo MCP server, it forwards each request to the Docsumo API over TLS. It stores no documents, extracted data or API keys, and has no tools that delete documents or cases.
Data protection

How a document is protected, from upload to deletion.

Docsumo is a hosted service: nothing to install on your servers. These are the protections at each step, colour-coded by type.

  • Encryption
  • Access
  • Network
  • Recovery and logging
  • Your control
  1. 01

    Upload

    Arrives encrypted

    • Encryption: TLS in transitHTTPS with certificates from an established authority
    • Access: Protected sign-inSSO, MFA, brute-force and script-injection protection
    • Access: Expiring review linksSigned links for outside reviewers expire after 1 day by default
  2. 02

    Process

    Read in a private network

    • Network: Private cloud networkA VPC on AWS and Google Cloud
    • Network: Encrypted admin accessServers reached only over SSH or VPN
    • Your control: Bound AI providersModel APIs under data protection terms
  3. 03

    Review

    Only the right people see it

    • Access: Document-type accessUsers open only the types they're given
    • Access: Assigned work onlyMembers see only documents assigned to them
    • Recovery and logging: Activity logEvery action recorded with a timestamp
  4. 04

    Store

    Encrypted and backed up

    • Encryption: AES-256 at restAll stored data encrypted
    • Network: No public database accessDeny-by-default firewall on every host
    • Recovery and logging: Daily backupsRestored in tests at least once a year
  5. 05

    Deliver

    Goes only where you send it

    • Your control: Your destinationsThe API, webhook or app you connect
    • Encryption: HTTPS webhooksOptional static IP, separate test and production URLs
    • Access: Per-user API keysEvery call attributable to a person
    • Encryption: Masked secretsCredentials for your systems stored masked, access by permission
  6. 06

    Delete

    Gone when you say

    • Your control: Delete anytimeDocuments and cases, in the app or by API
    • Your control: On requestWithin 30 days of an email to privacy@
    • Your control: At contract endAll content deleted automatically
Controls

The controls behind the audit.

Docsumo monitors its security program continuously in Sprinto. These are the controls published in our trust center, restated in plain English and grouped by area.

Data security

  • PassingEncryption at rest

    Every production database that stores customer data is encrypted at rest.

  • PassingStaff multi-factor authentication

    Every staff member with access to a critical system signs in with MFA.

  • PassingApproved access only

    Access to critical systems needs approval from authorized personnel, per person or per predefined role.

  • PassingData backups

    User and system data is backed up regularly to meet recovery time and recovery point objectives, and each backup's integrity is verified.

  • PassingBackup testing

    Backups are tested periodically for reliability and integrity.

  • PassingInfrastructure inventory

    Every infrastructure system is inventoried, with an accountable owner.

  • PassingCross-border transfers

    Set procedures meet regulatory requirements before personal data moves out of the region it was collected in.

  • PassingConsent

    Regulatory consent requirements are met before personal data is processed.

Status as shown in the Docsumo trust center on September 25, 2026. See live status ↗

Access control and audit

Decide who sees which documents. See everything they did.

Permissions by role, team and document type, with every review and approval recorded.

User roles in Docsumo
RoleWhat they can do
OwnerEverything, including account-level security settings for SSO and organization-wide MFA. One per account; ownership can be transferred.
AdminManages users, document types and settings, except those two security settings.
ModeratorReviews, approves and assigns documents, only within the document types they're given.
MemberReviews and approves only the documents assigned to them.
  • Single sign-on and MFA

    SSO over SAML 2.0, with a published Okta guide; the owner requests it in security settings. Any user can turn on MFA with an authenticator app, and the owner can enforce it for everyone. Google and Microsoft sign-in are also supported.

  • Access by document type and team

    Admins choose which document types each user can open. Within a type, an assigned team splits new documents, and supervisors can be alerted when one waits too long.

  • Activity logs

    Uploads, reviews, approvals, user actions and configuration changes, each timestamped. Filter by activity, date, user and mode (manual or automated), or search.

  • Password rules and a test environment

    Passwords need 8+ characters with upper and lower case, a number and a symbol, and are stored as hashes. Business and Enterprise plans add a separate test environment, so changes are checked before production.

Rich permissions control, audit logging and the test environment are part of the Business plan and above. See pricing.

Infrastructure and subprocessors

Where your data lives.

Docsumo runs on Amazon Web Services and Google Cloud Platform. You choose the region where your data is hosted:

  • United StatesN. Virginiaus-east-1
  • United StatesOhious-east-2
  • European UnionFrankfurteu-central-1
  • United KingdomLondoneu-west-2
  • IndiaMumbaiap-south-1
  • AustraliaSydneyap-southeast-2
  • SingaporeSingaporeap-southeast-1

Subprocessors

From our public subprocessor list, as of September 2026:

SubprocessorServiceLocation
Amazon Web Services, Inc. (AWS)Cloud hosting, storage and AI servicesUSA, EU, UK, AU, IN, SG
Google LLC (Google Cloud Platform)Cloud hosting, storage and AI servicesUSA, EU, UK, AU, IN, SG
MongoDB, Inc. (MongoDB Atlas)Database hostingUSA, EU, UK, AU, IN, SG
Anthropic, PBC (Anthropic)AI model APIUSA, EU
OpenAI OpCo, LLC (OpenAI)AI model APIUSA, EU
Cloudflare, Inc.CDN, DNS and network securityGlobal
Functional Software, Inc. (Sentry)Error and performance monitoringUSA

Systems you connect yourself, such as your API endpoint, a webhook, Google Sheets or Salesforce, receive data only at your request and sit outside Docsumo's control.

Retention and deletion

You decide how long we keep it.

Docsumo keeps your data only as long as it needs to provide the service, unless you delete it sooner.

  1. Anytime

    Delete a document in the app, or permanently through the API. Cases and all their data can be permanently deleted by API too.

  2. On request

    Email privacy@docsumo.com. Docsumo deletes the data within 30 days and confirms by email.

  3. At the end of your agreement

    All documents and extracted data are deleted automatically on the termination date and can't be recovered. Export what you need first.

  4. After account closure

    Personal data about your account is deleted no later than two months after the account is closed.

A written Data Retention Policy and Media Disposal Policy cover how data and storage media are disposed of.

Policies and documents

Everything your review will ask for.

27 security and privacy policies sit in the Docsumo trust center. Request access to view them. The SOC 2 Type 2 report is shared case by case: ask in the same request.

  • Security and access

    • Information Security
    • Access Control
    • Password
    • Encryption
    • Endpoint Security
    • Physical Security
    • Acceptable Usage
  • Data

    • Data Classification
    • Data Retention
    • Data Backup
    • Media Disposal
    • Confidentiality
  • AI

    • Artificial Intelligence Usage
    • Artificial Intelligence Data Security
  • Operations and resilience

    • Change Management
    • Vulnerability Management
    • Incident Management
    • PHI Breach Notification
    • Business Continuity
    • Disaster Recovery
  • Governance

    • Risk Management
    • Vendor Management
    • HR Security
    • Code of Business Conduct
    • ISMS Manual
    • ISMS Scope
    • System Description
Public
Contact
  • Personal data requests (access, correction, deletion): privacy@docsumo.com
  • Product support and incident reports: support@docsumo.com
  • SOC 2 report, BAA and DPA: trust center or your account team
Request access in the trust center ↗
Questions

What security reviewers ask us.

Is Docsumo SOC 2 Type 2 audited?

Yes. An independent CPA firm audits Docsumo's controls every year under SOC 2 Type 2. The report is shared case by case: request it in the Docsumo trust center (docsumo.trust.site) or from your account team.

Is Docsumo ISO 27001 certified?

Yes. Docsumo's information security management system is certified to ISO/IEC 27001:2022 by Ameri-Co Quality Standards Registech (certificate AMER30761). Docsumo was first certified in July 2023, and the current certificate was issued in August 2026.

Is Docsumo HIPAA compliant?

Yes, and Docsumo signs a Business Associate Agreement (BAA). Docsumo is HIPAA compliant for protected health information. Eligibility and healthcare teams use it for Medicaid applications and the documents inside them, with role-based permissions and an activity log of every action. Under its PHI Breach Notification Policy, a breach involving health data is reported to the customer in writing without unreasonable delay.

Will Docsumo sign a BAA or a DPA?

Yes. Docsumo signs a Business Associate Agreement (BAA) for protected health information and a Data Processing Agreement (DPA) for personal data under GDPR. Ask your account team for either.

Is our data encrypted?

Yes. Data in transit is encrypted with HTTPS and TLS, and data at rest is encrypted with AES-256. An external penetration test runs at least once a year. Production databases and SSH access are not reachable from the public internet, and every production host sits behind a deny-by-default firewall.

Does Docsumo use our documents to train AI models?

Not shared or third-party models. Docsumo reads documents with large language models called through APIs, and your documents and extracted data are not used to train shared or third-party models. Docsumo also never sells your data. Continuous Learning, an optional setting per document type, uses your reviewers' corrections to improve suggestions on similar documents in your own account.

Does Docsumo send documents to OpenAI or Anthropic?

Docsumo uses AI model APIs from Anthropic and OpenAI in its model waterfall, and your documents are not used to train shared or third-party models. Both are listed on Docsumo's public subprocessor list, processing in the USA and the EU, and like every subprocessor they are bound by confidentiality and data protection terms consistent with GDPR.

Where is our data stored?

You choose. Docsumo runs on Amazon Web Services and Google Cloud, and your data can be hosted in regions in the US (N. Virginia and Ohio), the EU (Frankfurt), the UK (London), India (Mumbai), Australia (Sydney) and Singapore. Docsumo is a hosted service; there is nothing to install on your own servers.

How long do you keep our documents?

As long as needed to provide the service, unless you delete them. Delete documents and cases at any time in the app or permanently through the API. Deletion requests to privacy@docsumo.com are completed within 30 days. When your agreement ends, all documents and extracted data are deleted automatically.

Can we control who sees which documents?

Yes. Each user has a role (Owner, Admin, Moderator or Member), and admins choose which document types each user can open. Members see only documents assigned to them. Every action is recorded in the activity log, which you can filter by user, activity, date and mode.

Do Docsumo employees get background checks and security training?

Yes. People are screened for security risk before they get access, complete security and privacy training when they join and security awareness training every year, and acknowledge company policies at onboarding and periodically after that.

How do we get your SOC 2 report and security policies?

Request access in the Docsumo trust center at docsumo.trust.site to view its 27 security and privacy policies, or ask your account team. The SOC 2 Type 2 report is shared case by case, and a BAA and DPA are available. If you are evaluating Docsumo, you can also book a demo and bring your security questionnaire.

Bring your security questionnaire to the demo.

We'll walk through how your documents are handled, from upload to deletion, and cover the SOC 2 report, BAA and DPA.