Security & Compliance Built Into the Platform — Not Bolted On
Documo is SOC 2 Type II audited, HIPAA compliant, and actively pursuing HITRUST e1 certification. These aren't feature-level checkboxes — they're architectural requirements that govern every workflow, transmission, and integration our platform handles.


Security Isn't a Feature.
It's the Foundation.
The Credentials Behind Every Documo Product

HITRUST e1 Certification
The HITRUST e1 (Essential, 1-Year) assessment validates an organization against the 44 most critical cybersecurity practices identified by the HITRUST Alliance — a curated subset of the full HITRUST CSF designed to establish a verified, independently assessed security baseline. Unlike self-reported compliance, e1 requires third-party validation by a HITRUST-authorized assessor. It is a meaningful, audited credential recognized across healthcare, not a checkbox.
Documo is currently in the HITRUST e1 assessment process. Once certified, customers will be able to access the certificate directly from our Trust Center. We will update this page upon completion.
- 44 essential cybersecurity controls validated.
- Third-party HITRUST Authorized External Assessor.
- 1-year certification cycle.
- Incorporates HIPAA security requirements.
- Independently validated — not self-attested.
- Accepted by health systems, payers, and government agencies.

SOC 2 Type II
SOC 2 (Service Organization Control 2) is a framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates a vendor’s security, availability, confidentiality, and privacy controls. The critical distinction of Type II over Type I: Type II audits test whether controls actually operated effectively over an extended observation period (typically 6–12 months), not just whether they were designed correctly. A vendor can produce a SOC 2 Type I report in weeks by designing controls on paper — a Type II report requires months of demonstrated operation.
The SOC 2 Type II report is available to qualified prospects and customers under NDA.
- SecuritySystems are protected against unauthorized access — physical and logical. Access controls, encryption, and intrusion detection are all tested.
- AvailabilitySystems are available for operation and use per our SLA commitments. Tested via uptime monitoring, incident response, and recovery procedures.
- PrivacyPersonal information is collected, used, retained, and disposed of in line with our privacy commitments.
- ConfidentialityInformation designated as confidential is protected per our commitments. PHI and sensitive business data are handled according to documented policies.

HIPAA Compliance
HIPAA requires covered entities and their business associates to implement three categories of safeguards to protect electronically protected health information (ePHI). Documo implements all required controls across all three categories — and provides a signed Business Associate Agreement to every healthcare account, regardless of plan or spend. We don’t treat HIPAA compliance as an enterprise-tier feature.
- AdministrativeRisk management, workforce training, and access controls.
- PhysicalFacility access and device use policies.
- TechnicalEncryption, automatic logoff, unique user IDs, audit controls.
- BAASigned for every account, no upcharge.

PIPEDA
PIPEDA governs how private-sector organizations in Canada collect, use, and disclose personal information in the course of commercial activity. For healthcare organizations operating in Canada or exchanging patient data across the US-Canada border, PIPEDA compliance is required in addition to HIPAA.
Documo supports both HIPAA and PIPEDA requirements, with Canadian data residency options available for eligible, PIPEDA-scoped workflows. Some platform data is always processed in the United States.
- Consent management and purpose limitation.
- Canadian data residency options available.
- Accountability designation and privacy officer.
- Data subject access and correction rights.
- Breach notification obligations per PIPEDA requirements.
- Openness and transparency obligations met.

Encryption Architecture
Documo encrypts every document and every transmission — data is encrypted in transit and at rest across processing, storage, and delivery. Encryption is enabled by default and managed through Google Cloud’s key management infrastructure, so key protection is handled by specialists and applied consistently across the platform.
- AES-256NIST FIPS 140-2 validated. Encrypted at rest by default.
- TLS 1.2Minimum TLS 1.2 enforced. TLS 1.0/1.1 disabled.
- AutomatedGoogle-managed key rotation.
- Managed KeysEncryption keys managed by Google Cloud KMS.
Infrastructure & Access Controls
Documo runs 100% on Google Cloud Platform (GCP). This isn’t a legacy system that was migrated to the cloud — Documo was architected as a cloud-native platform from the ground up, inheriting GCP’s enterprise security controls, physical data center certifications, and global infrastructure reliability by design.
For healthcare environments where downtime is not an option, Documo replicates all customer data across regions — so in the rare event of a regional disruption, our recovery point objective stays very low. Our compute environment is defined entirely as infrastructure-as-code, so we can re-provision it in another region quickly and with minimal manual work. This keeps recovery times short and supports the 99.9% uptime commitment healthcare workflows depend on.
- 100% cloud-native on Google Cloud Platform (GCP).
- 99.9% uptime SLA.
- Role-based access controls (RBAC) across all products.
- Comprehensive audit logging with immutable backups.
- Multi-region data replication with infrastructure-as-code recovery.
- Single sign-on (SSO) and directory sync (SCIM) support.
- Annual third-party penetration testing.
Compliance Documentation
Business Associate Agreement (BAA)
SOC 2 Type II Report
HITRUST e1 Certificate
Encryption & Security Overview
Data Processing Addendum (DPA)
Pre-Completed Security Questionnaire
We Make Your Security Review Straightforward
Start Your Vendor Review Today.
Security & Compliance FAQs
Documo completes an annual SOC 2 Type II audit, is HIPAA compliant with a BAA included, meets PIPEDA requirements, and is actively pursuing HITRUST e1 certification. All certifications apply platform-wide — not per-product. Current certification status is always available at trust.documo.com.
Platform-wide. HIPAA compliance, HITRUST certification, and SOC 2 Type II are architectural requirements — not product features. Every workflow, transmission, document, and API call on the Documo platform operates within the same certified security posture. There is no tiered or partial coverage.
HITRUST e1 (Essential, 1-Year) validates an organization against the 44 most critical cybersecurity practices defined by the HITRUST Alliance. Unlike HIPAA, which organizations can self-attest, HITRUST e1 requires independent third-party validation — making it a meaningful, audited credential. Documo is pursuing e1 as a next step in demonstrating security rigor beyond SOC 2, and it is recognized across major health systems, payers, and government agencies.
Most vendor risk documentation is available on-demand at trust.documo.com — including our SOC 2 Type II report, BAA, DPA, pre-completed questionnaire responses, and certification status. No waiting on a sales cycle.
Documo is 100% cloud-native on Google Cloud Platform (GCP) — built for the cloud from day one, not retrofitted. Data is hosted in the United States, and certain platform data is always processed in the US. Canadian data residency options are available for eligible, PIPEDA-scoped workflows. All customer data is replicated across regions, and our compute environment is defined as infrastructure-as-code, so we can recover quickly in the rare event of a regional disruption.
SOC 2 Type I tests whether controls are properly designed at a single point in time. SOC 2 Type II tests whether controls operated effectively over a sustained audit period (6–12 months). Type II is significantly more rigorous — a vendor can produce a Type I report in weeks by designing controls on paper. Our annual Type II audit tests sustained, real-world operation.
One Platform. One Security Standard.
Ready to Verify Documo's Security for Your Organization?
- HITRUST e1 in progress
- SOC 2 Type II audited
- BAA included
- 100% cloud-native