Security
You are handing us your source code. Here is what happens to it.
- Data in transit
- TLS 1.3
- Data at rest
- AES-256
- Region
- us-east-1, or eu-central-1 on request
- Report a vulnerability
- security@docsmithhq.com
Controls
What is in place today
Encryption
TLS 1.3 in transit. AES-256 at rest for everything in the database and object storage. Endpoint secrets and repository tokens are stored in a managed secrets service, encrypted with a customer-scoped key.
Source code handling
Docsmith reads the diff of a change and the pages that change can reach. It does not clone your repository to disk. Diff and page content live in memory for the duration of a sync and in a short-lived cache keyed to the sync, which expires within 24 hours by default and can be set to zero.
Model providers
Provider agreements exclude training on API traffic and set a zero-day retention where the provider supports it. The provider used for each step is recorded on the sync so you can audit exactly where a piece of code went.
Access control
SAML single sign-on and SCIM provisioning on Business. Role-based access with three roles: owner, reviewer and viewer. The GitHub app requests read access to code and write access only to the branches it opens.
Audit log
Every sync, draft, approval, rejection and settings change is written to an immutable log with actor, timestamp and source address. Exportable as JSON, retained for the life of the account on Business.
Availability
Multi-zone deployment in us-east-1 with automated failover, hourly database snapshots retained 35 days, and a tested restore procedure. Business plans carry a 99.9% monthly uptime commitment.
Compliance
Where we are, stated plainly
SOC 2 Type II
In progressObservation window opened in April 2026 with Prescott Assurance. Report expected in Q4 2026. We will not claim it before it exists.
GDPR
CompliantData processing agreement available on request and countersigned as part of any Business contract. EU data can be pinned to eu-central-1.
Penetration test
AnnualMost recent third-party test completed February 2026 by Vantage Point Labs. Summary letter available under NDA.
Sub-processors
PublishedThe current list is on the privacy page. Customers on Business receive 30 days' notice before a new sub-processor is added.
Data processing agreement
Our standard DPA incorporates the EU standard contractual clauses and the UK addendum, and lists every sub-processor. It is countersigned as part of any Business contract and is available before signature on request — write to security@docsmithhq.com.
Disclosure
Reporting a vulnerability
Email security@docsmithhq.com. We acknowledge within one business day and give you a status within five.
We will not take legal action against research conducted in good faith against your own account, and we will credit you in the changelog unless you would rather we did not. We do not currently run a paid bounty; we say so rather than implying one exists.
Please do not test against another customer’s data, and please do not run automated scanners against the production API — write to us and we will give you an environment.
Not yet done
- SOC 2 Type II report — observation window opened April 2026, expected Q4 2026.
- ISO 27001 — not started, and not planned before 2027.
- HIPAA — Docsmith is not designed for protected health information and we do not sign BAAs.
- FedRAMP — no.
- Self-hosted control plane — model routing can stay in your network today; the full control plane cannot.
Sub-processors are listed on the privacy page. Business customers get 30 days’ notice before one is added.
Get started
Send us your security questionnaire.
We answer them ourselves rather than routing you to a portal, and we will tell you which questions we fail.