Security and trust
What IT, information security and procurement need for vendor due diligence, on one page: where your documents go, how access is protected, and what we explicitly do not claim.
- Documents
- Uploaded original files are not retained after processing
- Hosting
- Application, database and backups in Germany, ISO/IEC 27001-certified data centre
- Transport
- TLS, HSTS
- Audit trail
- Hash-chained, recomputed every night and compared with a reference outside the database
Where your documents go
Trade documents carry sensitive commercial data. This is what happens to them after upload, as set out in our privacy policy.
- Uploaded original files are processed only transiently for the check you requested and are not retained after processing.
- Document content is sent to the AI service providers named in section 5.2 of the privacy policy, solely for the purpose of the check you requested.
- From the check we keep derived data: metadata about the check (timestamp, L/C reference number, overall result, number of errors and warnings) and the check report with our findings and the field values they refer to, including short source excerpts of at most 80 characters from which IBAN, BIC and card numbers have been redacted.
- Where the L/C has a reference number and its fields were reviewed, we may also retain the confirmed L/C terms (parties, banks, goods, amounts, dates, required documents) so they can be reused without reading the L/C again. Where the reader was unsure about a field, this happens only after every uncertain field was confirmed or corrected by a person. For standby letters of credit and guarantees, the confirmed terms also include the text of the undertaking as read from the document; it is kept under the same rules (only after uncertain fields were confirmed, two years, then deleted).
- The check report and any stored confirmed L/C terms remain available in your account for two years and are then deleted. The check metadata stays as the usage and billing overview (privacy policy, section 9).
- DocAccord does not use your documents to train AI models.
- Contributing anonymised checks to our test suite is opt-in, disabled by default, and can be withdrawn at any time in Settings.
Hosting and transport
The application and its database are hosted in Germany. AI processing is done by the providers named in the privacy policy, some of them in the USA under Standard Contractual Clauses.
- Operated on servers of Hetzner Online GmbH in Germany, with a data processing agreement in place.
- The data centre is ISO/IEC 27001-certified. The certification belongs to the data centre, not to DocAccord itself.
- Server access is by SSH key only; password logins are switched off. Repeated failed login attempts to the server are blocked automatically (fail2ban).
- All traffic is TLS-encrypted, with certificates renewed automatically.
Strict-Transport-Securityis set with the preload directive. - Security headers on every response, including
Content-Security-Policy,X-Content-Type-OptionsandX-Frame-Options. The API cannot be framed by other sites. - Every API response carries an
X-Request-ID, so a support request can be traced to the exact call. - Server logs are rotated automatically and kept only for a short period.
Access and accounts
DocAccord is built for business customers.
- Passwords are stored only as bcrypt hashes. New passwords need at least 10 characters (12 for administrators), may not contain the name part of the email address, and very common passwords are refused.
- Sessions use short-lived tokens (12 hours, 30 minutes for administrators) that are renewed while you are active, for at most seven days after sign-in (administrators: 12 hours). Logging out ends every session of the account on every device, and a password change invalidates all other sessions immediately.
- The email address must be verified before the account can be used.
- Optional two-step sign-in: a 6-digit code sent by email, stored only as a hash, with limited attempts per sign-in and per IP address.
- Instead of the emailed code, an authenticator app (TOTP, RFC 6238) can be used, so a compromised mailbox alone is not enough to sign in. The app's key is stored encrypted, every code works only once, and the 10 recovery codes are stored only as hashes.
- After 10 wrong passwords or 10 wrong codes within 15 minutes, sign-in for that account is paused for 15 minutes and the account owner is notified by email (at most once a day).
- Sign-in, registration and password reset are rate-limited against automated attacks. Checks are rate-limited per user or per API key.
- Team seats on subscription plans: members work under the owner's account. The owner and team admins manage seats; only the owner manages billing and can request account deletion.
Audit trail
Who changed what, and when: security and compliance-relevant events are recorded in a tamper-evident log.
- Logged events include registration, sign-in (successful and failed), password changes, email verification, and administrative actions on a customer account.
- The log is hash-chained: each entry includes the hash of the one before it, so a changed or deleted entry shows up when the chain is checked. The chain is recomputed in full every night and compared with a reference kept outside the database. The application never deletes entries. After 12 months it removes the plaintext email address and IP address from an entry; the entry itself stays. Entries written before the separation of personal data from the chain in autumn 2026 still hold them in plaintext, because changing an entry would break the chain; on request their processing is restricted instead (see the privacy policy).
- When a DocAccord administrator opens the content of a customer's stored check report, that access is recorded in the same log.
- Risk findings that require it need a sign-off by a named user, recorded in the audit trail.
- You can see your own account's activity history in the app.
- A share link to a check and the address of a calendar feed are random secrets stored only as hashes. A share link expires after 14 days (30 at most), both can be turned off at any time, and every visit to a share link is recorded in the same log and in your account history.
- Every check can be exported as a PDF audit report.
Partner API security
API access is available on the Enterprise plan and is re-checked on every call.
- API keys are shown exactly once, at creation. We store only a SHA-256 hash and a short prefix. A lost key is replaced, not recovered.
- Keys carry a recognisable prefix (
da_live_,da_test_) so secret scanners can detect a leaked key. - Each key carries scopes:
lc:readfor reading checks and usage,lc:writefor creating checks. - New keys expire after 365 days by default, unless you choose a different duration.
- Keys can be revoked at any time, by you or by DocAccord. Creation, revocation and scope changes are recorded in the audit trail.
- Webhooks are signed with HMAC-SHA256 over the timestamp and the raw body (
X-DocAccord-Signature,X-DocAccord-Timestamp). Because the timestamp is signed, a captured delivery cannot be replayed with a new date. - Webhook endpoints must use HTTPS.
Your rights and your data
The data controller under GDPR is DocAccord Group Ltd, 71-75 Shelton Street, London WC2H 9JQ, United Kingdom.
Companies House registration number 17451988
- You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15-21 GDPR).
- An informal message to privacy@docaccord.com is enough. We respond within one month at the latest.
- The account owner can request deletion in Settings. The account is then deleted, or anonymised where statutory retention obligations (e.g. HGB, AO) apply.
- A data processing agreement is available.
- Supervisory authority for complaints (Art. 77 GDPR): LDI NRW, Düsseldorf.
What we do not claim
For your vendor assessment, what does not apply matters as much. So it is stated here explicitly.
DocAccord itself holds no ISO/IEC 27001 certification and no SOC 2 report. The ISO/IEC 27001 certification belongs to the data centre that hosts us.
An EU representative under Art. 27 GDPR will be appointed. Until then, you can reach us at privacy@docaccord.com.
No Data Protection Officer is appointed, as the statutory requirements (Art. 37 GDPR, § 38 BDSG) are not met.
A check result is decision support. It makes no legally binding decision and does not replace the bank's independent examination.
There is no contractual uptime commitment (SLA).
No external penetration test has been carried out yet.
Report a vulnerability
Please report security issues by email to security@docaccord.com. This is the same address as in our security.txt.
- Describe what you found, how to reproduce it, and which URL or endpoint is affected.
- Test only against your own account. Do not access, change or delete other customers' data, and do not run load or denial-of-service tests.
- A person reads every report, usually within two working days. We confirm receipt and tell you when the issue is fixed.
- We do not run a paid bug bounty programme.
Questions from your vendor review?
Choose the Security topic in the contact form. To report a vulnerability, email security@docaccord.com. A person reads every message, usually within two working days.