Security

Security built in,
not bolted on.

Every document session runs through encrypted channels, verified identities, and tamper-evident records. The controls your clients and compliance teams expect are on by default — no add-ons required.

Controls

What protects every document session.

Identity verification

Every signer is verified before signing.

Docuplete uses OTP verification to confirm the signer's identity via their email address before accepting a signature — producing a legally defensible audit trail on every submission.

1

Client receives a unique link

Each document session has its own tokenised URL. The link is single-use — opening it on a different device does not start a separate session.

2

OTP sent to their email

Before the client can sign, Docuplete sends a one-time code to their email address. They enter it to confirm they control the inbox.

3

Signature accepted, audit trail sealed

The verified signature event — with timestamp, IP, device, and OTP confirmation — is written to the immutable audit trail and appended to the PDF as a signing certificate page.

In transit

End-to-end protection for every document.

TLS in transit

All data between clients, Docuplete's servers, and your integrations is transmitted over TLS. Combined with AES-256-GCM at rest, client data is protected through its entire lifecycle.

Multi-tenant isolation

Every query is scoped to your organisation. Data from other Docuplete customers is inaccessible by design — enforced at the database and API middleware level.

SOC 2-aligned controls

Docuplete's security architecture — encryption, audit trails, access controls, and tenant isolation — is built around SOC 2 Trust Services Criteria. SOC 2 Type II audit in progress.

Security questions?
Talk to us.

We're happy to walk through Docuplete's controls with your security or compliance team.

Contact us

Related

Security features in detail