Compliance Overview
Docamint is built with strong security and privacy practices. While Docamint does not claim formal certifications such as SOC 2, HIPAA, or PCI, it is designed to operate within environments that meet your organization’s compliance requirements.
Certifications
No Formal Certifications
Docamint does not currently hold certifications such as SOC 2, ISO 27001, HIPAA, or PCI. Instead, the
platform focuses on strong engineering practices, secure data handling, and deployment flexibility.
Deployment
Deploy in Your Own Environment
Organizations with strict compliance requirements can deploy Docamint inside their own cloud or data
center. This allows you to enforce your own controls, policies, and certifications.
Data
Controlled Data Handling
Docamint processes your data only to generate documents. No payloads are used for training, analytics,
or shared with third parties. You retain full ownership of your templates and outputs.
Encryption
Encryption Standards
All traffic is encrypted in transit using HTTPS/TLS, and templates or data stored in Docamint Cloud are
encrypted at rest in tenant-specific storage. These are engineering practices, not a claim of certification.
Access
Access Control
User authentication and roles are managed by your calling application; Docamint authenticates API
requests with your API key. Self-hosted deployments let you enforce your own IAM policies end to end.
Audit
Audit Logging
Document generation events can be logged to support traceability and internal compliance reviews. Logs include
timestamps, template versions, and processing outcomes, and contain no personally identifiable information (PII).
Summary
Compliance Summary
Docamint’s compliance posture is based on transparency and strong engineering practices:
- No formal certifications (SOC 2, ISO 27001, HIPAA, PCI)
- Strong security and privacy controls
- Encryption in transit and at rest (tenant-specific storage)
- Access controlled by your application via API keys
- Audit logs for traceability (no PII)
- Self-hosted option for regulated industries
These principles allow Docamint to operate safely within organizations that have strict compliance requirements, especially when deployed inside your own environment.