Trust center preview
Security designed around sensitive documents
Clear separation between current measures, planned certifications, and customer-configurable controls.
Current measures
TLS for data in transit, encryption at rest in managed infrastructure, secret isolation, input validation, restrictive browser headers, and no permanent demo-file storage.
Planned assurance
Independent security assessment and certification work are planned. Dox Engine does not currently claim SOC 2, ISO 27001, HIPAA, GDPR, or PCI certification.
Enterprise discussion
Retention windows, regional deployment, single sign-on, audit logs, dedicated infrastructure, and custom incident terms are available for enterprise discussion.
Shared responsibility
Customers must protect API keys, limit access, classify submitted data, configure retention, and validate outputs before high-impact decisions.
