Security built for financial and health data
Docsumo is SOC 2 Type 2 audited, ISO/IEC 27001:2022 certified, and HIPAA and GDPR compliant. This page shows how we handle your documents, who can see them, where they are stored, which AI models touch them and how long we keep them.
Last reviewed September 25, 2026
Docsumo is an intelligent document processing (IDP) platform. It runs as a hosted service on Amazon Web Services and Google Cloud, holds SOC 2 Type 2 and ISO/IEC 27001:2022, encrypts data in transit (TLS) and at rest (AES-256), and gives you role-based access, single sign-on, enforced MFA and an activity log of every action in your account.
The short version for your security review.
- Audited and certified ↓SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA and GDPR. Reports and policies on request.
- AI and your data ↓Which models read your documents, and which outside providers are involved.
- Encrypted and tested ↓TLS in transit, AES-256 at rest. External penetration test every year.
- Access control ↓Four roles, access by document type, SAML SSO, enforced MFA.
- Activity logs ↓Every upload, review, approval and setting change, filterable.
- Deletion on your terms ↓Delete in the app or by API. Everything is deleted when your agreement ends.
Audited, not self-declared.
Lending, insurance, healthcare and eligibility teams send Docsumo bank statements, tax returns, ACORD forms and Medicaid applications. These programs cover that work.

SOC 2 Type 2
AuditedAn independent CPA firm audits Docsumo's controls every year. A Type 2 audit tests that controls operated effectively across a full audit period, not only that they were designed well on one day.
Docsumo received its first SOC 2 report in 2021. The controls behind the audit are listed further down this page.
SOC 2 Type 2 report: shared case by case. Request it in the trust center or ask your account team.
ISO/IEC 27001:2022
CertifiedDocsumo's information security management system is certified to ISO/IEC 27001:2022 by Ameri-Co Quality Standards Registech (certificate AMER30761). Docsumo was first certified in July 2023; the current certificate was issued in August 2026, with yearly surveillance audits.
Scope: design, development, maintenance, technical support, sales and marketing of the Docsumo platform.
ISO 27001 certificate: request access in the trust center or ask your account team.

HIPAA
CompliantDocsumo is HIPAA compliant for protected health information. Eligibility and revenue-cycle teams use it for Medicaid applications and the bank statements, pay stubs and IDs inside them.
Docsumo signs a Business Associate Agreement (BAA) with customers who process protected health information. Under its PHI Breach Notification Policy, a breach involving health data is reported to the customer in writing without unreasonable delay.
BAA: available, ask your account team. HIPAA policies: request access in the trust center.

GDPR
CompliantFor the documents you upload and the data extracted from them, Docsumo is the data processor. For account data such as names, emails and billing details, Docsumo is the controller.
Docsumo appoints a privacy officer, runs data protection impact assessments, checks consent before processing personal data and follows set procedures for moving it across regions. Data can stay in the EU (Frankfurt) or the UK (London).
DPA: available, ask your account team. Access, correction or deletion requests: privacy@docsumo.com, completed within 30 days. Full terms in the Privacy Policy.
- Encryption at rest
- AES-256
- Encryption in transit
- HTTPS with TLS
- Penetration testing
- External, every year
- ISO 27001 certified
- Since July 2023
Which models read your documents.
Your documents are processed to return your data. Here is the path a document takes, which outside providers are involved and what you can switch on or off.
- Your documentUpload, email, API, or Google Drive, SharePoint and S3.
- Docsumo on AWS and Google CloudEncrypted in transit and at rest.
- Model waterfallLarge language models via API. When one is unsure of a field, the next checks it.
- Your reviewersFields below your threshold go to the review queue.
- Your systemsData goes only where you send it.
- No shared or third-party model training
- Docsumo reads your documents with large language models called through APIs. Your documents and extracted data are not used to train shared or third-party models.
- Bound like every subprocessor
- Docsumo carries out due diligence before engaging any subprocessor, including the AI model providers. Each is bound by confidentiality agreements and data protection terms consistent with GDPR.
- Governed by written AI policies
- An Artificial Intelligence Usage Policy and an Artificial Intelligence Data Security Policy set how AI is used at Docsumo and how data sent to models is protected. Both are in the trust center.
- Your data is never sold
- Docsumo does not sell your personal data or document data under any circumstances.
- Controls in your account
- The AI Extractor is set per document type: choose Basic, Standard or Advanced, or switch it off. Continuous Learning, which uses your reviewers' corrections to improve suggestions on similar documents, is also on or off per document type, and applies only to your account.
- Your own AI agents
- If you connect Claude, Cursor or an app built on the OpenAI API through the Docsumo MCP server, it forwards each request to the Docsumo API over TLS. It stores no documents, extracted data or API keys, and has no tools that delete documents or cases.
How a document is protected, from upload to deletion.
Docsumo is a hosted service: nothing to install on your servers. These are the protections at each step, colour-coded by type.
- Encryption
- Access
- Network
- Recovery and logging
- Your control
- 01
Upload
Arrives encrypted
- Encryption: TLS in transitHTTPS with certificates from an established authority
- Access: Protected sign-inSSO, MFA, brute-force and script-injection protection
- Access: Expiring review linksSigned links for outside reviewers expire after 1 day by default
- 02
Process
Read in a private network
- Network: Private cloud networkA VPC on AWS and Google Cloud
- Network: Encrypted admin accessServers reached only over SSH or VPN
- Your control: Bound AI providersModel APIs under data protection terms
- 03
Review
Only the right people see it
- Access: Document-type accessUsers open only the types they're given
- Access: Assigned work onlyMembers see only documents assigned to them
- Recovery and logging: Activity logEvery action recorded with a timestamp
- 04
Store
Encrypted and backed up
- Encryption: AES-256 at restAll stored data encrypted
- Network: No public database accessDeny-by-default firewall on every host
- Recovery and logging: Daily backupsRestored in tests at least once a year
- 05
Deliver
Goes only where you send it
- Your control: Your destinationsThe API, webhook or app you connect
- Encryption: HTTPS webhooksOptional static IP, separate test and production URLs
- Access: Per-user API keysEvery call attributable to a person
- Encryption: Masked secretsCredentials for your systems stored masked, access by permission
- 06
Delete
Gone when you say
- Your control: Delete anytimeDocuments and cases, in the app or by API
- Your control: On requestWithin 30 days of an email to privacy@
- Your control: At contract endAll content deleted automatically
The controls behind the audit.
Docsumo monitors its security program continuously in Sprinto. These are the controls published in our trust center, restated in plain English and grouped by area.
Data security
- PassingEncryption at rest
Every production database that stores customer data is encrypted at rest.
- PassingStaff multi-factor authentication
Every staff member with access to a critical system signs in with MFA.
- PassingApproved access only
Access to critical systems needs approval from authorized personnel, per person or per predefined role.
- PassingData backups
User and system data is backed up regularly to meet recovery time and recovery point objectives, and each backup's integrity is verified.
- PassingBackup testing
Backups are tested periodically for reliability and integrity.
- PassingInfrastructure inventory
Every infrastructure system is inventoried, with an accountable owner.
- PassingCross-border transfers
Set procedures meet regulatory requirements before personal data moves out of the region it was collected in.
- PassingConsent
Regulatory consent requirements are met before personal data is processed.
Network security
- PassingEncryption in transit
Data in transit is kept confidential with standard encryption, including HTTPS with TLS.
- PassingNo public database access
Production databases and SSH access to infrastructure are not reachable from the public internet.
- PassingDeny-by-default firewall
Every production host sits behind a firewall that denies traffic unless it's allowed.
- PassingSecurity event logging
Critical systems generate audit events for security-relevant actions.
- PassingAnomaly detection
Audit events are reviewed and analyzed to detect suspicious activity and threats.
- PassingCapacity and denial-of-service
Critical assets are monitored continuously, with capacity alerts, to keep performance up and protect against denial-of-service attacks.
- PassingTest data protection
Customer data used outside production gets the same protection as in production.
- PassingControl impact review
System information is reviewed to catch anything that affects how internal controls work.
Product and app security
- PassingVulnerability scanning
Regular vulnerability scans run against the Docsumo platform.
- PassingPenetration testing
An external penetration test, covering web application and client-based attacks, runs at least once a year.
- PassingTracked remediation
Every vulnerability is tracked and fixed under a documented vulnerability management procedure.
- PassingChange control
Documented procedures govern every change to the operating environment.
- PassingChange approval
Changes to the operating environment need approval before they go in.
- PassingSession timeouts
Sign-in sessions to the cloud provider console end after a set time.
- PassingCurrent privacy notice
The latest information about the service, including the privacy notice, is on the website.
People
- PassingBackground screening
People are screened for security risk before they are given access.
- PassingQualified security staff
Security-related positions are filled by people with the right skills.
- PassingTraining at onboarding
New staff complete security and privacy training when they join.
- PassingAnnual security training
All staff complete security awareness training every year, and records are kept.
- PassingRole-relevant training
Security and privacy training matches each person's job.
- PassingPolicy acknowledgement
Staff acknowledge company policies when they join and again periodically.
- PassingCode of conduct
A documented code of business conduct sets behavioral standards.
- PassingPerformance reviews
People in client-facing, IT, engineering and security roles are evaluated periodically.
Governance and risk
- PassingInformation Security Officer
Senior management appoints an Information Security Officer to run the security and privacy program.
- PassingPrivacy officer
A privacy officer oversees compliance with privacy regulations.
- PassingContinuous monitoring
Sprinto tracks the health of the security program and reports it to the Information Security Officer.
- PassingManagement review
Senior management reviews and approves policies, standards and procedures at planned intervals or after significant change.
- PassingAnnual risk assessment
A formal risk assessment runs every year. Each risk is scored on likelihood and impact and mapped to mitigations.
- PassingAnnual vendor risk assessment
Vendors critical to security commitments are identified and assessed every year.
- PassingSubprocessor oversight
Service providers are evaluated periodically, and safeguards are in place whenever personal data is shared with them.
- PassingData protection impact assessments
DPIAs are run periodically to assess the regulatory risk of processing personal data.
- PassingSegregation of duties
Responsibilities are split across the organization to reduce risk to customers.
- PassingDefined roles
An org chart, reviewed and approved by senior management every year, sets authority and responsibility.
- PassingRegulatory register
A list of the legal and regulatory requirements that apply to information security is maintained.
- PassingPolicy retention
Policy documents are kept for at least six years.
Incidents and assets
- PassingCustomer incident reporting
Customers are told how to report failures, incidents and concerns about the service.
- PassingStaff incident reporting
Staff know how to report failures, incidents and concerns through the security policies.
- PassingContingency testing
Regular tests and exercises check that the contingency plan works.
- PassingEndpoint inventory
Every staff device is inventoried, with an accountable owner.
- PassingAsset ownership
Each asset has an assigned owner responsible for protecting it.
- PassingInventory updates
Inventories are updated with every installation, removal and system update.
- PassingPrivacy statements on forms
Forms that collect personal information carry a privacy statement.
Status as shown in the Docsumo trust center on September 25, 2026. See live status ↗
Decide who sees which documents. See everything they did.
Permissions by role, team and document type, with every review and approval recorded.
| Role | What they can do |
|---|---|
| Owner | Everything, including account-level security settings for SSO and organization-wide MFA. One per account; ownership can be transferred. |
| Admin | Manages users, document types and settings, except those two security settings. |
| Moderator | Reviews, approves and assigns documents, only within the document types they're given. |
| Member | Reviews and approves only the documents assigned to them. |
Single sign-on and MFA
SSO over SAML 2.0, with a published Okta guide; the owner requests it in security settings. Any user can turn on MFA with an authenticator app, and the owner can enforce it for everyone. Google and Microsoft sign-in are also supported.
Access by document type and team
Admins choose which document types each user can open. Within a type, an assigned team splits new documents, and supervisors can be alerted when one waits too long.
Activity logs
Uploads, reviews, approvals, user actions and configuration changes, each timestamped. Filter by activity, date, user and mode (manual or automated), or search.
Password rules and a test environment
Passwords need 8+ characters with upper and lower case, a number and a symbol, and are stored as hashes. Business and Enterprise plans add a separate test environment, so changes are checked before production.
Rich permissions control, audit logging and the test environment are part of the Business plan and above. See pricing.
Where your data lives.
Docsumo runs on Amazon Web Services and Google Cloud Platform. You choose the region where your data is hosted:
- United StatesN. Virginia
us-east-1 - United StatesOhio
us-east-2 - European UnionFrankfurt
eu-central-1 - United KingdomLondon
eu-west-2 - IndiaMumbai
ap-south-1 - AustraliaSydney
ap-southeast-2 - SingaporeSingapore
ap-southeast-1
Subprocessors
From our public subprocessor list, as of September 2026:
| Subprocessor | Service | Location |
|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud hosting, storage and AI services | USA, EU, UK, AU, IN, SG |
| Google LLC (Google Cloud Platform) | Cloud hosting, storage and AI services | USA, EU, UK, AU, IN, SG |
| MongoDB, Inc. (MongoDB Atlas) | Database hosting | USA, EU, UK, AU, IN, SG |
| Anthropic, PBC (Anthropic) | AI model API | USA, EU |
| OpenAI OpCo, LLC (OpenAI) | AI model API | USA, EU |
| Cloudflare, Inc. | CDN, DNS and network security | Global |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | USA |
Systems you connect yourself, such as your API endpoint, a webhook, Google Sheets or Salesforce, receive data only at your request and sit outside Docsumo's control.
You decide how long we keep it.
Docsumo keeps your data only as long as it needs to provide the service, unless you delete it sooner.
Anytime
Delete a document in the app, or permanently through the API. Cases and all their data can be permanently deleted by API too.
On request
Email privacy@docsumo.com. Docsumo deletes the data within 30 days and confirms by email.
At the end of your agreement
All documents and extracted data are deleted automatically on the termination date and can't be recovered. Export what you need first.
After account closure
Personal data about your account is deleted no later than two months after the account is closed.
A written Data Retention Policy and Media Disposal Policy cover how data and storage media are disposed of.
Everything your review will ask for.
27 security and privacy policies sit in the Docsumo trust center. Request access to view them. The SOC 2 Type 2 report is shared case by case: ask in the same request.
Security and access
- Information Security
- Access Control
- Password
- Encryption
- Endpoint Security
- Physical Security
- Acceptable Usage
Data
- Data Classification
- Data Retention
- Data Backup
- Media Disposal
- Confidentiality
AI
- Artificial Intelligence Usage
- Artificial Intelligence Data Security
Operations and resilience
- Change Management
- Vulnerability Management
- Incident Management
- PHI Breach Notification
- Business Continuity
- Disaster Recovery
Governance
- Risk Management
- Vendor Management
- HR Security
- Code of Business Conduct
- ISMS Manual
- ISMS Scope
- System Description
- Personal data requests (access, correction, deletion): privacy@docsumo.com
- Product support and incident reports: support@docsumo.com
- SOC 2 report, BAA and DPA: trust center or your account team
What security reviewers ask us.
Is Docsumo SOC 2 Type 2 audited?
Yes. An independent CPA firm audits Docsumo's controls every year under SOC 2 Type 2. The report is shared case by case: request it in the Docsumo trust center (docsumo.trust.site) or from your account team.
Is Docsumo ISO 27001 certified?
Yes. Docsumo's information security management system is certified to ISO/IEC 27001:2022 by Ameri-Co Quality Standards Registech (certificate AMER30761). Docsumo was first certified in July 2023, and the current certificate was issued in August 2026.
Is Docsumo HIPAA compliant?
Yes, and Docsumo signs a Business Associate Agreement (BAA). Docsumo is HIPAA compliant for protected health information. Eligibility and healthcare teams use it for Medicaid applications and the documents inside them, with role-based permissions and an activity log of every action. Under its PHI Breach Notification Policy, a breach involving health data is reported to the customer in writing without unreasonable delay.
Will Docsumo sign a BAA or a DPA?
Yes. Docsumo signs a Business Associate Agreement (BAA) for protected health information and a Data Processing Agreement (DPA) for personal data under GDPR. Ask your account team for either.
Is our data encrypted?
Yes. Data in transit is encrypted with HTTPS and TLS, and data at rest is encrypted with AES-256. An external penetration test runs at least once a year. Production databases and SSH access are not reachable from the public internet, and every production host sits behind a deny-by-default firewall.
Does Docsumo use our documents to train AI models?
Not shared or third-party models. Docsumo reads documents with large language models called through APIs, and your documents and extracted data are not used to train shared or third-party models. Docsumo also never sells your data. Continuous Learning, an optional setting per document type, uses your reviewers' corrections to improve suggestions on similar documents in your own account.
Does Docsumo send documents to OpenAI or Anthropic?
Docsumo uses AI model APIs from Anthropic and OpenAI in its model waterfall, and your documents are not used to train shared or third-party models. Both are listed on Docsumo's public subprocessor list, processing in the USA and the EU, and like every subprocessor they are bound by confidentiality and data protection terms consistent with GDPR.
Where is our data stored?
You choose. Docsumo runs on Amazon Web Services and Google Cloud, and your data can be hosted in regions in the US (N. Virginia and Ohio), the EU (Frankfurt), the UK (London), India (Mumbai), Australia (Sydney) and Singapore. Docsumo is a hosted service; there is nothing to install on your own servers.
How long do you keep our documents?
As long as needed to provide the service, unless you delete them. Delete documents and cases at any time in the app or permanently through the API. Deletion requests to privacy@docsumo.com are completed within 30 days. When your agreement ends, all documents and extracted data are deleted automatically.
Can we control who sees which documents?
Yes. Each user has a role (Owner, Admin, Moderator or Member), and admins choose which document types each user can open. Members see only documents assigned to them. Every action is recorded in the activity log, which you can filter by user, activity, date and mode.
Do Docsumo employees get background checks and security training?
Yes. People are screened for security risk before they get access, complete security and privacy training when they join and security awareness training every year, and acknowledge company policies at onboarding and periodically after that.
How do we get your SOC 2 report and security policies?
Request access in the Docsumo trust center at docsumo.trust.site to view its 27 security and privacy policies, or ask your account team. The SOC 2 Type 2 report is shared case by case, and a BAA and DPA are available. If you are evaluating Docsumo, you can also book a demo and bring your security questionnaire.
Bring your security questionnaire to the demo.
We'll walk through how your documents are handled, from upload to deletion, and cover the SOC 2 report, BAA and DPA.
