DOCSUPRA › Enterprise Compliance Studio
The Enterprise Compliance Studio, explained: from a folder of phone photos to a filing-ready ZIP.
The short answer. It is a desk inside DOCSUPRA for teams. You choose a department and a destination, drop up to 500 files, and every file is measured against that destination’s published rule, fixed, and delivered in one ZIP with an audit CSV and a certificate carrying each file’s SHA-256. It runs in the browser on your own machines. There is no upload step, because there is no server to upload to.
Most document platforms want the documents on their servers first and the compliance report second. This one is built the other way round: the audit happens where the file already is, and what leaves the building is a record of hashes and verdicts, never the images.
What the desk is
DOCSUPRA is one piece of software with three studios. The Compliance Studio repairs and exports one document at a time. The Integrity Scanner reads what a file says about its own history. The Enterprise Compliance Studio is the third: a desk for teams that receive documents in volume, organised by department and destination, with the team console inside it. It opens at docsupra.com/#pro for Professional Team and Corporate Studio.
Everything runs in the browser using the machine’s own processor and memory. There is no upload endpoint in the product. Your IT lead can confirm it in two minutes: process a real document with the network monitor open, watch the upload counter stay at zero, then disconnect and watch it keep working.
How a batch goes through, step by step
Set the desk up for the department
Choose the department and the destination. There are 28 destination presets, each with the date it was verified against the official portal and the source; delivery format, dimensions and DPI can be overridden when a portal asks for something specific.
Add the documents
Drag and drop, Upload, Folder or a ZIP: JPEG, PNG, HEIC, TIFF and PDF, up to 500 files per run and 30 MB per file inside a ZIP. Or send the client a capture link and let their phone do the photographing.
Read the audit
Every file is measured against the destination’s rule: format, pixels, DPI, file size, sharpness and orientation, plus an integrity signal from the file’s own metadata. Each row says what passes, what needs a look and what is missing.
Fix and export
One ZIP with every fixed file, an audit CSV and certificate.pdf: per file, the SHA-256 of what was delivered, what was fixed on export and, for anything that cannot comply, exactly what is missing to comply with that destination.
Record the batch
The batch can be recorded to the organisation log: file names, hashes, sizes and verdicts, never the images. Under compliance mode the record is mandatory and pseudonymous, and each record is chained to the previous one by hash so the log cannot be edited without breaking the chain.
Run the team from the desk
The team console lives inside the Enterprise Studio: people and seats, single sign-on, usage per person and department, the organisation log, compliance mode, API keys and webhooks.
The ten modules on the desk
| Module | What it does |
|---|---|
| Batch queue | Drop up to 500 files per run. One bad file does not stop the batch; it is reported. |
| Fix & export (ZIP) | One ZIP with every fixed file, in the format, dimensions and DPI the destination asks for, or the ones you set. |
| Audit CSV | A dated CSV per batch: file, verdict, what was fixed, what is still missing. |
| Certificate | certificate.pdf inside the ZIP: the SHA-256 of each delivered file, the destination and its published rule, and for files that cannot comply, what is missing. |
| Capture links | Clients photograph the document on their own phone; the photo is checked and fixed there and never touches a server. Up to 100 links per batch, 30-day expiry. |
| Organisation log | Who audited what, when: file names, hashes, sizes and verdicts. Never the images. Each record is chained to the previous one by hash and can be verified. |
| Team & seats | People, seats and single sign-on with Microsoft Entra ID, Okta, Google Workspace or any OpenID Connect provider. |
| Compliance mode | HIPAA, GLBA, GDPR or your own policy: what the desk records, for how long, and how an unattended desk behaves. |
| Integrity signals | A risk level per file from what the file says about its own history, computed on this machine. |
| Install as an app | Chrome or Edge: menu, then Install app. It opens in its own window and keeps working without a connection. |
Compliance mode: HIPAA, GLBA, GDPR or your own policy
Compliance mode is a set of rules your organisation enforces on every Enterprise Compliance Studio desk. Nothing in it uploads a document. The rules govern what is recorded about each batch (identifiers, hashes, verdicts), for how long, and how an unattended desk behaves: whether recording a batch is mandatory before the export is released, the retention window for records, whether records carry pseudonyms instead of file names (the GDPR setting), whether a file name that looks like an identifier gets a warning, and whether the desk clears itself when left alone.
The organisation log is chained: every record carries the hash of the previous one, and the console can verify the whole chain at any time. Policy changes, purges, key and webhook changes are recorded in the same log, so the trail of administration is part of the evidence. An evidence PDF summarises the policy in force and the state of the log for an auditor.
What it is not. Compliance mode does not make an organisation compliant by itself, and we do not sell a certification. It gives your programme the two things reviewers ask for first: a written policy that the software actually enforces, and a log that cannot be edited without breaking its chain.
Machine-to-machine access without touching a document
Your case-management, CRM or SIEM system can read the organisation without ever seeing a file. An API key reads the organisation log, verifies the chain, reads usage and policy and creates capture links; it cannot download and it cannot administer. Signed webhooks push three events, batch recorded, batch delivered and admin action, with an HMAC-SHA256 signature you verify on your side. If you build software, the Integrity SDK runs the same file-integrity analysis inside your own application. The developer guide has every endpoint and the signature check.
Where the documents go
Nowhere. The file that entered the desk stays on that machine; the ZIP that leaves it goes wherever your team sends it. What the licence server ever sees is a count of downloads, the hashes and verdicts your people chose to record, and the identifiers of who did it. There is no data-processing relationship to describe for documents, no retention schedule to agree for them, and no supplier breach that becomes your notification letter. The privacy review for IT spells it out step by step, and the trust center carries the DPA, SLA, sub-processor list and enterprise agreement.
What it costs a team
Both plans include the same software. Corporate Studio adds people, a named support contact and invoice billing.
Prices are in USD and exclude any tax that applies in your country; Stripe calculates it and shows it before you pay. Only the monthly plans renew, and they cancel in one click from the Stripe receipt.
See every plan →Questions
Which plans include the Enterprise Compliance Studio?
Both team plans: Professional Team ($149 per month, up to 3 people) and Corporate Studio ($349 per month, 10 people included and $29 per extra seat, up to 500 people). The desk, the team console, compliance mode, API access and the Integrity Scanner are in both.
How many documents can one batch hold?
Up to 500 files per run. JPEG, PNG, HEIC, TIFF and PDF, dropped one by one, as a folder or as a ZIP. One file that cannot comply is reported; it does not stop the batch.
Do the documents leave our machines?
No. There is no upload endpoint. Every file is measured and fixed on the machine that opened it. What can be recorded, if your people choose to, is file names, hashes, sizes and verdicts, never the images.
What is in the ZIP?
Every fixed file in the format, dimensions and DPI of the destination (or the ones you set), a dated audit CSV, and certificate.pdf with the SHA-256 of each delivered file and, where a file cannot comply, what is missing to comply with that destination.
Does compliance mode make us HIPAA or GDPR compliant?
No software does that by itself, and we do not claim it. Compliance mode enforces a written policy on every desk and keeps a hash-chained log that cannot be edited without breaking the chain. Those are the pieces reviewers ask for first; your programme is still yours.
Can our systems connect to it?
Yes. API keys read the organisation log, verify the chain, read usage and policy and create capture links; signed webhooks push batch and admin events; the Integrity SDK runs the file-integrity analysis inside your own software. Keys cannot download or administer.
See the desk with your own documents
Professional Team and Corporate Studio open it. The audit runs before anything is downloaded, so you can judge every verdict first.
Open the Enterprise StudioMore for teams
Made and copyrighted © 2026 by Soelys Muñoz. DocVerifyPro™ is her trademark. All rights reserved. How to recognise the real site.