DOCSUPRA Open the Enterprise Studio

DOCSUPRATrust center

Trust center · reviewed 18 September 2026

What a reviewer needs, in one place.

DOCSUPRA is document compliance software for individuals and enterprise organizations. This page links every document a security, legal or procurement team asks for, and states plainly what we have, what we do not have yet, and where each claim can be verified without asking us.

The one fact that shapes every answer. Documents are processed inside the user’s own browser. There is no upload endpoint: the software cannot receive a document even if asked to. What we hold is a billing record (from Stripe) and licence data. Disconnect from the internet and the software keeps working — that is the test.

Documents

Security & architecture

Data flow, controls, vulnerability management, incident response, business continuity, and the full vendor-questionnaire answer set (SIG Lite / CAIQ style).

Read the security page →

Sub-processors

Every third party that touches any data, what it receives, and how we notify changes.

See the list →

Data Processing Addendum

GDPR Article 28 terms with Standard Contractual Clauses for the little personal data we do process (billing and licence data).

Read the DPA →

Service Level Agreement

Availability commitment, support response times and escalation for Professional Team and Corporate Studio.

Read the SLA →

Enterprise Subscription Agreement

The negotiable agreement for organisations buying on a purchase order: term, seats, liability, IP, confidentiality.

Read the agreement →

Accessibility

Conformance statement against WCAG 2.1 AA and a VPAT-style summary for Section 508 procurement.

Read the statement →

System requirements

Browsers, virtual desktops, proxies and offline operation — what IT needs to allow.

Read the requirements →

Status & privacy

Live status checks run from your own browser, and the privacy policy that names every sub-processor.

Status →   Privacy →   Privacy review for IT →

Controls at a glance

ControlStatusDetail
Document content received by usNoNo upload endpoint exists. Processing is in-browser. Verifiable offline.
Encryption in transitYesTLS 1.2+ on every host; HSTS with preload; automatic HTTPS upgrade.
Encryption at restN/ANo document data is stored anywhere by us. Billing data is held by Stripe (PCI DSS Level 1). Licence data is stored in Cloudflare KV, encrypted at rest by the platform.
Content Security PolicyYesStrict CSP: scripts only from this origin and Stripe; connections only to the licence service, Stripe and Cloudflare analytics. Frame-ancestors none.
Authentication for teamsYesPer-person sign-in by email link; seats counted per person; administrators can remove a person at any time.
Single sign-on (SAML / OIDC)YesOpenID Connect with Microsoft Entra ID, Okta, Google Workspace and any OIDC provider; just-in-time provisioning restricted to your domain.
Audit logYesPer-batch record of file name, SHA-256, dimensions, verdict, person and time. Never the image. Exportable as CSV/JSON; optional organisation-level log.
Usage reportingYesMonthly report per member and department, downloadable from the administration console.
Vulnerability disclosureYesPublished at /.well-known/security.txt; acknowledgement within 2 business days.
Incident responseYesWritten procedure with 72-hour customer notification for any incident affecting your data. See Incident response.
Independent audit (SOC 2 / ISO 27001)NoNot performed. Scope is small (no customer documents are ever held). Stated openly rather than implied.
Penetration testNoNo third-party test has been commissioned yet. Scope and rules of engagement are available on request; the application has no server-side document handling to test.

How to verify instead of trust

  1. Open the studio, open your browser’s network monitor, process a real document: no request carries the file. The only hosts contacted are listed in the Content Security Policy.
  2. Turn off the network and process another document: it completes.
  3. Hash a delivered file and compare it with the receipt on its compliance report at /verify.
  4. Fetch /.well-known/security.txt for the disclosure contact and policy.

What we do not claim. No SOC 2 or ISO 27001 report exists yet; the day one does, it is named here with the auditor. We do not verify document authenticity and give no legal, immigration or tax advice.

Requesting documents

Signed copies of the DPA, SLA and Enterprise Subscription Agreement, a completed vendor questionnaire in your own template, or a W-9: write to security@docsupra.com. Response within one business day for Professional Team and Corporate Studio customers.