Security & Compliance
Built Into the Platform — Not Bolted On

Documo is SOC 2 Type II audited, HIPAA compliant, and actively pursuing HITRUST e1 certification. These aren't feature-level checkboxes — they're architectural requirements that govern every workflow, transmission, and integration our platform handles.

HITrust e1, SOC 2 Type II, HIPAA + BAA Included, PIPEDA, AES-256 + TLS 1.2
Female doctor and nurse reviewing something on a laptop

Security Isn't a Feature.

It's the Foundation.

Most vendors apply compliance as a layer on top of their product. Documo builds from the security requirements down — so certifications reflect how the platform actually operates, not how we describe it in marketing.
Architecture-First
Security controls are defined before code is written. Encryption, access boundaries, and audit requirements are architectural requirements, not post-launch additions.
Independently Verified
We don't self-attest. Our certifications and audit reports are issued by independent third parties — AICPA-registered CPA firms, HITRUST-authorized assessors, and independent penetration testers.
Continuously Maintained
Certifications aren't earned once and forgotten. SOC 2 is re-audited annually, HITRUST re-certified on schedule, and security controls are tested through continuous monitoring.
Architectural, Not Additive
Security controls are defined at the platform level — not applied product by product. A fax, a processed document, an API call, a secure message: all share the same certified infrastructure.

The Credentials Behind Every Documo Product

Independent auditors verify what we claim. Here is exactly what each certification covers and what it means for your organization.
HITRUST e1

HITRUST e1 Certification

Coming Soon
Health Information Trust Alliance. Essential, 1-Year Assessment.
Independently validated healthcare security — Documo's HITRUST e1 certification is actively in progress.

The HITRUST e1 (Essential, 1-Year) assessment validates an organization against the 44 most critical cybersecurity practices identified by the HITRUST Alliance — a curated subset of the full HITRUST CSF designed to establish a verified, independently assessed security baseline. Unlike self-reported compliance, e1 requires third-party validation by a HITRUST-authorized assessor. It is a meaningful, audited credential recognized across healthcare, not a checkbox.

Documo is currently in the HITRUST e1 assessment process. Once certified, customers will be able to access the certificate directly from our Trust Center. We will update this page upon completion.

  • 44 essential cybersecurity controls validated.
  • Third-party HITRUST Authorized External Assessor.
  • 1-year certification cycle.
  • Incorporates HIPAA security requirements.
  • Independently validated — not self-attested.
  • Accepted by health systems, payers, and government agencies.
SOC 2 Type II

SOC 2 Type II

AICPA Trust Services Criteria · Annual Independent Audit.
Operating effectiveness tested over time — not just design intent.

SOC 2 (Service Organization Control 2) is a framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates a vendor’s security, availability, confidentiality, and privacy controls. The critical distinction of Type II over Type I: Type II audits test whether controls actually operated effectively over an extended observation period (typically 6–12 months), not just whether they were designed correctly. A vendor can produce a SOC 2 Type I report in weeks by designing controls on paper — a Type II report requires months of demonstrated operation.

The SOC 2 Type II report is available to qualified prospects 
and customers under NDA. 

  • Security
    Systems are protected against unauthorized access — physical and logical. Access controls, encryption, and intrusion detection are all tested.
  • Availability
    Systems are available for operation and use per our SLA commitments. Tested via uptime monitoring, incident response, and recovery procedures.
  • Privacy
    Personal information is collected, used, retained, and disposed of in line with our privacy commitments.
  • Confidentiality
    Information designated as confidential is protected per our commitments. PHI and sensitive business data are handled according to documented policies.
HIPAA Compliance

HIPAA Compliance

Health Insurance Portability and Accountability Act
All three safeguard categories. BAA at no additional charge.

HIPAA requires covered entities and their business associates to implement three categories of safeguards to protect electronically protected health information (ePHI). Documo implements all required controls across all three categories — and provides a signed Business Associate Agreement to every healthcare account, regardless of plan or spend. We don’t treat HIPAA compliance as an enterprise-tier feature.

  • Administrative
    Risk management, workforce training, and access controls.
  • Physical
    Facility access and device use policies.
  • Technical
    Encryption, automatic logoff, unique user IDs, audit controls.
  • BAA
    Signed for every account, no upcharge.
PIPEDA

PIPEDA

Personal Information Protection and Electronic Documents Act.
Cross-border healthcare organizations covered — one vendor, two jurisdictions.

PIPEDA governs how private-sector organizations in Canada collect, use, and disclose personal information in the course of commercial activity. For healthcare organizations operating in Canada or exchanging patient data across the US-Canada border, PIPEDA compliance is required in addition to HIPAA.

Documo supports both HIPAA and PIPEDA requirements, with Canadian data residency options available for eligible, PIPEDA-scoped workflows. Some platform data is always processed in the United States.

  • Consent management and purpose limitation.
  • Canadian data residency options available.
  • Accountability designation and privacy officer.
  • Data subject access and correction rights.
  • Breach notification obligations per PIPEDA requirements.
  • Openness and transparency obligations met.

Encryption Architecture

AES-256 at Rest. TLS 1.2 in Transit.
AES-256 encryption at rest and TLS 1.2 in transit

Documo encrypts every document and every transmission — data is encrypted in transit and at rest across processing, storage, and delivery. Encryption is enabled by default and managed through Google Cloud’s key management infrastructure, so key protection is handled by specialists and applied consistently across the platform.

  • AES-256
    NIST FIPS 140-2 validated. Encrypted at rest by default.
  • TLS 1.2
    Minimum TLS 1.2 enforced. 
TLS 1.0/1.1 disabled.
  • Automated
    Google-managed key rotation.
  • Managed Keys
    Encryption keys managed by Google Cloud KMS.

Infrastructure & Access Controls

GCP-Native. Multi-Region Data Replication. RBAC. 99.9% SLA.
Built for the cloud from day one — not retrofitted, not on-premises.

Documo runs 100% on Google Cloud Platform (GCP). This isn’t a legacy system that was migrated to the cloud — Documo was architected as a cloud-native platform from the ground up, inheriting GCP’s enterprise security controls, physical data center certifications, and global infrastructure reliability by design.

For healthcare environments where downtime is not an option, Documo replicates all customer data across regions — so in the rare event of a regional disruption, our recovery point objective stays very low. Our compute environment is defined entirely as infrastructure-as-code, so we can re-provision it in another region quickly and with minimal manual work. This keeps recovery times short and supports the 99.9% uptime commitment healthcare workflows depend on.

  • 100% cloud-native on Google Cloud Platform (GCP).
  • 99.9% uptime SLA.
  • Role-based access controls (RBAC) across all products.
  • Comprehensive audit logging with immutable backups.
  • Multi-region data replication with infrastructure-as-code recovery.
  • Single sign-on (SSO) and directory sync (SCIM) support.
  • Annual third-party penetration testing.

Compliance Documentation

Our SOC 2 Type II report, information security and privacy policies, penetration test summaries, and architecture diagrams are all maintained in our Trust Center. You accept our standard confidentiality terms once, and that single NDA covers every document. No sales cycle, no waiting.

Business Associate Agreement (BAA)

Standard BAA covering all Documo products for healthcare organizations. Signed and countersigned at no additional cost. Enterprise accounts may request custom agreement language.
Visit Trust Center

SOC 2 Type II Report

Full audit report from our most recent SOC 2 Type II examination. Available to qualified prospects and existing customers under mutual NDA. Covers all five Trust Services Criteria.
Visit Trust Center

HITRUST e1 Certificate

Official HITRUST e1 certification from the HITRUST Alliance. Assessment currently in progress — the certificate will be available in our Trust Center upon completion.
Visit Trust Center

Encryption & Security Overview

Technical documentation covering Documo's encryption architecture, key management practices, access control design, and infrastructure security controls.
Visit Trust Center

Data Processing Addendum (DPA)

Covers GDPR-aligned data processing obligations, subprocessor list, and international data transfer mechanisms. Required for organizations subject to EU data protection law.
Visit Trust Center

Pre-Completed Security Questionnaire

SIG Lite and CAIQ responses covering the most common vendor risk assessment questions. Saves your security team days of back-and-forth. Available with an NDA on file.
Visit Trust Center

We Make Your Security Review Straightforward

Documo's security team supports enterprise procurement, providing everything your IT and compliance teams need for vendor risk assessments — without slowing your evaluation.
Pre-Completed SIG 
Lite & CAIQ
Standard questionnaire responses ready to submit. Saves your team 10–20 hours of follow-up questions.
Security Review Calls
We join your IT security team's vendor review calls — CISO to CISO, or security engineer to security engineer.
Custom Documentation Requests
Sub-processor lists, penetration test summaries, data flow diagrams, architecture documentation — available
under NDA.
1–2 Business Day Response
Security review requests are handled by our dedicated security team, not routed through general support queues.

Start Your Vendor Review Today.

Most compliance documentation, questionnaire responses, and certification 
status updates are available on-demand — no waiting on a sales cycle.

Security & Compliance FAQs

Documo completes an annual SOC 2 Type II audit, is HIPAA compliant with a BAA included, meets PIPEDA requirements, and is actively pursuing HITRUST e1 certification. All certifications apply platform-wide — not per-product. Current certification status is always available at trust.documo.com.

Platform-wide. HIPAA compliance, HITRUST certification, and SOC 2 Type II are architectural requirements — not product features. Every workflow, transmission, document, and API call on the Documo platform operates within the same certified security posture. There is no tiered or partial coverage.

HITRUST e1 (Essential, 1-Year) validates an organization against the 44 most critical cybersecurity practices defined by the HITRUST Alliance. Unlike HIPAA, which organizations can self-attest, HITRUST e1 requires independent third-party validation — making it a meaningful, audited credential. Documo is pursuing e1 as a next step in demonstrating security rigor beyond SOC 2, and it is recognized across major health systems, payers, and government agencies.

Most vendor risk documentation is available on-demand at trust.documo.com — including our SOC 2 Type II report, BAA, DPA, pre-completed questionnaire responses, and certification status. No waiting on a sales cycle.

Documo is 100% cloud-native on Google Cloud Platform (GCP) — built for the cloud from day one, not retrofitted. Data is hosted in the United States, and certain platform data is always processed in the US. Canadian data residency options are available for eligible, PIPEDA-scoped workflows. All customer data is replicated across regions, and our compute environment is defined as infrastructure-as-code, so we can recover quickly in the rare event of a regional disruption.

SOC 2 Type I tests whether controls are properly designed at a single point in time. SOC 2 Type II tests whether controls operated effectively over a sustained audit period (6–12 months). Type II is significantly more rigorous — a vendor can produce a Type I report in weeks by designing controls on paper. Our annual Type II audit tests sustained, real-world operation.

Yes. A single BAA covers all Documo products the customer uses — cloud fax, document processing, API, and future products. You won’t need separate BAAs for each product. Enterprise customers may request custom BAA language for specific legal requirements.

One Platform. One Security Standard.

Documo's certifications aren't applied feature by feature. HITRUST, SOC 2 Type II, and HIPAA compliance are built into the platform architecture that powers everything we build — so every workflow, integration, and API call inherits the same security posture.
Cloud Fax
HIPAA-compliant cloud faxing with zero hardware, full audit trails, and BAA included.
Document Processing
Intelligent classification, extraction, and routing — running on the same certified infrastructure.
API
Embed secure fax and document processing into your product — compliance inherited by default.
Direct Secure Messaging
HIPAA-compliant secure messaging via API — the same platform-level security, different transport.

Ready to Verify Documo's Security 
for Your Organization?

Get instant access to compliance documentation, book a security
review call, or start a demo today. No waiting, no gatekeeping.
  • HITRUST e1 in progress
  • SOC 2 Type II audited
  • BAA included
  • 100% cloud-native