Security & trust

Your clients’ work, protected by design.

Docsiv holds the documents you send to clients, so security isn’t a feature, it’s the foundation. Here’s how we protect your work, your brand, and your clients’ data.

TLSEncrypted in transit
RLSPer-client isolation
Your domainAuto-renewing SSL
Audit trailOn every signature

Encrypted end to end

All traffic runs over TLS, and your documents and data are encrypted at rest by our infrastructure providers. Nothing moves or sits in the clear.

Isolated at the database

Every workspace and client profile is separated with Postgres Row-Level Security — enforced in the database, not just in app code. One client can never see another.

Layered access model

Team members work in the dashboard, clients see only their branded portal, and each document supports view, comment, or edit share links with explicit scopes.

Your domain, automatic SSL

Branded portals run on your own custom domain with certificates provisioned and renewed automatically. Clients never see a Docsiv URL.

Tamper-evident signing

E-signatures use hashed signing tokens, HMAC-verified OTP, and an append-only audit trail, with a certificate of completion generated for every signed document.

Your data stays yours

Export any document to PDF, PPTX, DOCX, PNG, or SVG at any time. You own your content, and we never sell it.

Compliance, honestly.

We’re a young company and we’d rather be straight about where we are. Here’s what’s in place today and what we’re building toward.

Available

GDPR-aligned + DPA

A Data Processing Agreement is available, and our subprocessors are listed publicly.

Available

Audit logging

Append-only audit events for signing, plus per-document activity and email logs.

In progress

SOC 2 Type II

We are building toward SOC 2 Type II as part of our path to enterprise readiness.

 Have a security question or need our security overview? Talk to us.

Security your clients can rely on.

Protection built into every document and portal you share.