Skip to content

Security

You are handing us your source code. Here is what happens to it.

This page is written for the person who has to sign off on the purchase. Where something is in progress it says so, and where we have not done something yet it says that too.
Data in transit
TLS 1.3
Data at rest
AES-256
Region
us-east-1, or eu-central-1 on request
Report a vulnerability
security@docsmithhq.com

Controls

What is in place today

Encryption

TLS 1.3 in transit. AES-256 at rest for everything in the database and object storage. Endpoint secrets and repository tokens are stored in a managed secrets service, encrypted with a customer-scoped key.

Source code handling

Docsmith reads the diff of a change and the pages that change can reach. It does not clone your repository to disk. Diff and page content live in memory for the duration of a sync and in a short-lived cache keyed to the sync, which expires within 24 hours by default and can be set to zero.

Model providers

Provider agreements exclude training on API traffic and set a zero-day retention where the provider supports it. The provider used for each step is recorded on the sync so you can audit exactly where a piece of code went.

Access control

SAML single sign-on and SCIM provisioning on Business. Role-based access with three roles: owner, reviewer and viewer. The GitHub app requests read access to code and write access only to the branches it opens.

Audit log

Every sync, draft, approval, rejection and settings change is written to an immutable log with actor, timestamp and source address. Exportable as JSON, retained for the life of the account on Business.

Availability

Multi-zone deployment in us-east-1 with automated failover, hourly database snapshots retained 35 days, and a tested restore procedure. Business plans carry a 99.9% monthly uptime commitment.

Compliance

Where we are, stated plainly

SOC 2 Type II

In progress

Observation window opened in April 2026 with Prescott Assurance. Report expected in Q4 2026. We will not claim it before it exists.

GDPR

Compliant

Data processing agreement available on request and countersigned as part of any Business contract. EU data can be pinned to eu-central-1.

Penetration test

Annual

Most recent third-party test completed February 2026 by Vantage Point Labs. Summary letter available under NDA.

Sub-processors

Published

The current list is on the privacy page. Customers on Business receive 30 days' notice before a new sub-processor is added.

Data processing agreement

Our standard DPA incorporates the EU standard contractual clauses and the UK addendum, and lists every sub-processor. It is countersigned as part of any Business contract and is available before signature on request — write to security@docsmithhq.com.

Disclosure

Reporting a vulnerability

Email security@docsmithhq.com. We acknowledge within one business day and give you a status within five.

We will not take legal action against research conducted in good faith against your own account, and we will credit you in the changelog unless you would rather we did not. We do not currently run a paid bounty; we say so rather than implying one exists.

Please do not test against another customer’s data, and please do not run automated scanners against the production API — write to us and we will give you an environment.

Not yet done

  • SOC 2 Type II report — observation window opened April 2026, expected Q4 2026.
  • ISO 27001 — not started, and not planned before 2027.
  • HIPAA — Docsmith is not designed for protected health information and we do not sign BAAs.
  • FedRAMP — no.
  • Self-hosted control plane — model routing can stay in your network today; the full control plane cannot.

Sub-processors are listed on the privacy page. Business customers get 30 days’ notice before one is added.

Get started

Send us your security questionnaire.

We answer them ourselves rather than routing you to a portal, and we will tell you which questions we fail.