Infrastructure security
How DocAccord is built, run and protected: hosting, network, encryption, AI processing, development, monitoring and recovery. Written for information security, IT and procurement.
- Hosting
- Germany: application, database, backups. AI reading: EU and USA under SCCs.
- Documents
- Uploaded original files are not retained after processing
- Backups
- Every 5 minutes, encrypted, off-site, restore tested
- Audit trail
- Hash-chained, recomputed every night and compared with a reference outside the database. Entries are never deleted.
- Email and web
- DMARC reject, security.txt, HSTS with the preload directive
- Breach notice
- Within 48 hours at the latest
Our commitments
What never happens to your trade documents, on any plan.
- We do not sell your documents or the data read from them, and we do not use them for advertising.
- DocAccord does not train AI models on your documents.
- One customer's data is never visible to another. Every query is bound to the signed-in account.
- Contributing anonymised checks to our test suite is opt-in, off by default, and can be withdrawn at any time.
Architecture
A deliberately small attack surface: one way in, one application, a database with no internet access, and no file storage for uploads.
- The only way in from the internet is a reverse proxy that terminates TLS and sets security headers. No other service publishes a port.
- Network: a host firewall (ufw) allows incoming connections only on ports 22, 80 and 443 and drops everything else. Hetzner's DDoS protection filters denial-of-service flood traffic in the host's network before it reaches the server.
- Server access is by SSH key only; password logins are switched off. Repeated failed login attempts to the server are blocked automatically (fail2ban).
- Email and web hygiene: a DMARC policy of
rejectfor docaccord.com, asecurity.txtfor vulnerability reports, andStrict-Transport-Securitywith the preload directive. All three can be checked from outside. - The application and the web front end run in separate containers with health checks.
- The database sits on its own internal network with no route to the internet. Only the application can reach it; other services on the same server cannot.
- There is no object or file storage for uploaded documents. Uploaded files are processed only transiently for the requested check and are not retained afterwards.
- For the check you request, document content is sent over TLS to the AI service providers named in section 5.2 of the privacy policy.
Hosting
The application, the database and every backup are in Germany.
- Operated on servers of Hetzner Online GmbH in Germany, with a data processing agreement in place.
- The data centre is ISO/IEC 27001-certified (see Hetzner's certificate page). The certification belongs to the data centre, not to DocAccord.
- The AI providers are in the EU and the USA. Transfers to the USA rely on EU Standard Contractual Clauses (see the privacy policy).
Encryption and hashing
We encrypt where it protects against a concrete attack. What is not encrypted is stated here too.
- In transit: TLS 1.2 and 1.3, certificates renewed automatically,
Strict-Transport-Securitywith the preload directive. - Passwords are stored only as bcrypt hashes, API keys and recovery codes only as SHA-256 hashes.
- Authenticator-app keys and bank details are encrypted at field level.
- We do not encrypt the server's system disk (operating system, application, logs) ourselves; there, physical protection rests on the data centre's ISO/IEC 27001 controls.
- Backups are encrypted as they are created (age). The server holds only the public key: it can write backups but cannot read them. The private key is kept by the founder, outside the infrastructure.
- The database and its transaction log sit on their own volume, encrypted with LUKS2 (AES-256). It unlocks at boot with a key kept on a different disk: a copy of either one alone reveals nothing. The volume's recovery passphrase and header backup are kept by the company, outside the infrastructure. Because the volume unlocks automatically at boot, the running server can read the database.
Data lifecycle
How long each kind of data stays. Deletion after a retention period runs automatically every night; deleting an account starts with the account owner's request.
- Uploaded original files: not retained after processing.
- Check report with findings and stored confirmed L/C terms: two years in your account, then deleted. Check metadata (timestamp, reference, result, number of errors and warnings) stays as the billing and usage overview (privacy policy, section 9).
- Audit trail: entries are never deleted. Email and IP addresses are removed after 12 months. Entries written before the separation of personal data from the chain in autumn 2026 still hold them in plaintext, because changing an entry would break the hash chain; on request their processing is restricted instead.
- Backups: 14 days, the continuous transaction log 15 days. Data erased from the live database is gone from every backup within 30 days at the latest.
- Export: the account owner can download all account data as one JSON file at any time (Settings).
- Account deletion: the account owner requests it in Settings and confirms their identity. The account stays active for 30 days so the request can be withdrawn, with a reminder a week before. A nightly job then deletes it, or anonymises it where statutory retention applies. A renewing subscription must be cancelled and team members removed first. Stored report content is removed when the account is deleted.
- Payment cards: DocAccord never receives or stores card numbers. Payments run through Paddle as Merchant of Record, in Paddle's own checkout window.
Access and permissions
Password, session and API key details are on the Security and trust page. This is what matters for operations.
- Two-step sign-in by emailed code or authenticator app (TOTP). It is mandatory for DocAccord administrators.
- Administrator sessions expire after 30 minutes without activity and end 12 hours after sign-in at the latest; customer sessions expire after 12 hours, at most seven days after sign-in.
- When an administrator opens the content of a customer's report, that access is recorded in the audit trail.
- API keys with scopes (read, write), expiry and revocation; webhooks signed with HMAC-SHA256 over timestamp and body.
- Sign-in with Google or Apple is available.
AI processing, kept in check
The AI reads the documents. Whether there is a discrepancy is decided by a fixed rule engine, not by the model.
- Findings come from a deterministic rule engine derived from UCP 600 and ISBP 821. No model is asked for a verdict.
- Before every check you see every field that was read. Fields the reading was unsure about must each be confirmed or corrected, and the report shows what was confirmed.
- IBANs, BIC codes and card numbers are removed from the text before it is sent.
- Document text is treated as third-party content: instructions written inside a document are reported, not followed.
- Every check stores the rule set version and reader version it ran on, so a result can be traced later.
- Usage limits per account and per API key, plus a global circuit breaker, stop runaway AI calls.
- Assistant answers are labelled as AI-generated (Art. 50 EU AI Act).
- What our AI providers' own public terms say about retention and training, read on 29 September 2026 (linked). We state a point only where the provider's terms say it.
- Anthropic: API inputs and outputs are deleted from its systems within 30 days of receipt or generation, with the exceptions the article lists, for example enforcement of its usage policy and legal duties (data retention article, 1 July 2026). Its commercial terms, effective 17 June 2025, say Anthropic may not train models on customer content (commercial terms).
- Mistral: for most of its APIs, inputs and outputs are kept for the time needed to generate the output and then for 30 rolling days to monitor abuse, unless zero data retention is activated (Mistral privacy policy, effective 3 September 2026).
- Google: used only for the tariff lookup. It sends the goods description, HS code and the countries of origin and destination, not the document itself (section 3.11 of the privacy policy describes what the lookup sends). Under the terms for paid services of its API, effective 23 March 2026, Google does not use prompts and responses to improve its products and logs them for a limited period to detect abuse; with Grounding with Google Search, which the lookup uses, Google stores prompts and outputs for 30 days (API terms).
Secure development
How a change reaches production, and where a one-maintainer setup has limits.
- Changes go through a pull request into a protected main branch. The backend and frontend test jobs are required status checks before a merge.
- Every ready pull request runs the backend tests and a secret scan. Frontend tests, lint and type checks run when frontend files change, and the dependency audit when a lockfile changes. Static code analysis and a dependency audit also run nightly on the main branch.
- Dependencies are monitored automatically and updated regularly; production installs exactly locked versions.
- As our release process, a change runs on a staging environment before production.
- One maintainer, no second human reviewer. Compensating controls: required CI checks, staging before production (our release process), locked versions.
- Tests and CI never call an AI provider and never use customer data.
Monitoring and incidents
Monitoring that still alerts when the application itself is down.
- Automated checks run every 5 minutes around the clock, independent of the application: they check the website, the application and the database and alert the operator by email. There is no staffed 24/7 on-call. The checks run on the same server, so they do not report a failure of the server itself.
- The audit trail is hash-chained. The chain is recomputed in full every night and compared with a reference kept outside the database. Entries are never deleted; email and IP addresses are removed after 12 months (for older entries see Data lifecycle).
- Repeated failed sign-ins pause the account for 15 minutes and notify the account owner.
- Unusual AI usage is evaluated and reported every hour.
- We notify the account owner of a personal data breach without undue delay, and at the latest within 48 hours (data processing agreement, Art. 33 GDPR).
- We take vulnerability reports at security@docaccord.com, as published in our
security.txt.
Backup and recovery
Backups only count once a restore has worked. We have tested that.
- Continuous backup: the database's transaction log is encrypted and copied off-site at least every 5 minutes. On top of that, a full encrypted backup every night and before every production deployment.
- Three copies: two on the server, one off-site on a separate Hetzner Storage Box in Germany with its own access. On top of that, daily server images kept by the host.
- Tested on 28 September 2026: a full restore onto a new, empty server from the off-site copy (every table and row equal to live), and a restore to a chosen second.
- Maximum data loss (RPO): about 10 minutes. Recovery on a new server (RTO): within 4 hours.
- DocAccord runs on one server in one data centre. There is no automatic failover to a second site; recovery is a restore from backup, following a documented procedure.
Compliance status
Where we stand, without anticipating what an auditor still has to confirm.
- GDPR: a data processing agreement is available; the record of processing activities and the AI system inventory are maintained alongside the code.
- Data centre: ISO/IEC 27001-certified (Hetzner, certificate page).
- DocAccord: we are building our information security management system along ISO/IEC 27001. No certificate or audit report exists yet.
- We answer the security questionnaires from your vendor review.
What we do not claim
For your vendor assessment, what does not apply matters as much. So it is stated here explicitly.
- There is no contractual uptime commitment (SLA).
- No external penetration test has been carried out yet.
- There is no automatic failover to a second site.
- DocAccord itself holds no ISO/IEC 27001 certificate and no SOC 2 report. The ISO/IEC 27001 certification belongs to the data centre that hosts us.
Questions from your vendor review?
Choose the Security topic in the contact form. A person reads every message, usually within two working days.