Trust center

Pre-answered security questionnaire

These answers were reviewed against the implementation and public repository. They describe the controls in place today and state gaps directly.

Last reviewed: July 29, 2026

Need an answer that is not covered here? Email support@dockosha.com.

Enforced controls at a glance

  • TLS in transit and AES-256 at rest on Supabase-managed infrastructure
  • Postgres row-level security for tenant isolation
  • Workspace-owner and per-surface authorization
  • Trigger-driven internal audit logging
  • Server-enforced public-link gates and server-side PDF watermarking
  • Consent-aware analytics with Global Privacy Control honored

Company & compliance

What is DocKosha?

DocKosha is a document-sharing and virtual data-room product with one normal feature edition under AGPL-3.0-or-later. DocYantra is the mandatory direct 0.0.26 dependency; managed DocKosha Cloud provides hosting. Enterprise licensing is available only through a separate signed agreement.

Do you hold SOC 2 or ISO 27001 certifications?

No. We do not hold SOC 2 or ISO 27001 certifications. Instead, we publish the controls implemented today and maintain the enforced-controls list below for security reviewers.

How is the software licensed?

The DocKosha source is licensed under AGPL-3.0-or-later. There is one normal feature edition, and DocYantra is the mandatory direct 0.0.26 dependency. Enterprise licensing is available only through a separate signed agreement.

Does the Cloud product send product telemetry?

The hosted Cloud product uses consent-gated analytics. EU, EEA, UK, and unknown-region visitors require opt-in; non-EU visitors can opt out; Global Privacy Control is honored and turns analytics and session replay off. We do not make a no-phone-home claim for the Cloud product.

Data protection

How is data encrypted?

Data is protected with TLS in transit and AES-256 at rest on Supabase-managed infrastructure.

What customer data does DocKosha process?

The service processes account and workspace data, uploaded documents, generated PDFs, sharing settings, billing records, transactional email details, and viewer information only where the selected link settings collect it.

Where is customer data hosted?

See the subprocessor list. Deployment regions are pending verification from the relevant provider account settings and are not guessed on that page.

What retention controls are implemented?

Viewer analytics are pruned at 365 days. Workspace owners can configure retention from 1 to 20 previous document versions; the current version is not counted. Other records follow the applicable product and legal retention requirements.

How can a customer request deletion?

Account deletion and privacy-rights requests are accepted through /data-request. Requests are handled subject to applicable legal retention requirements.

Access control

How are tenants isolated?

Postgres row-level security is applied on every tenant table to enforce workspace-scoped access.

How do users authenticate?

DocKosha uses Supabase Auth with passwordless magic links and Google OAuth. Authenticated routes enforce the session boundary server-side.

What authorization model is used?

A workspace owner has full workspace control. Other members receive per-surface access levels for documents and data rooms, with none, viewer, or editor access and optional explicit per-room grants.

Are administrative actions audited?

Yes. Relevant workspace activity is recorded in an immutable, trigger-driven audit log that is available to workspace owners.

Application security

Which document-access protections are server enforced?

Public sharing gates are server enforced and include passwords, email OTP, expiry, one-time open, allowlists, NDA acceptance, and download rules.

How are document watermarks applied?

For supported PDF and convertible-document downloads that require watermarking, watermarks are burned into the delivered PDF bytes server-side. A required watermark failure fails closed rather than returning the raw file.

Can DocKosha stop screenshots?

No. Screenshot controls are a best-effort deterrent. Browsers cannot block operating-system capture, and the product states that limitation plainly.

Are public authentication surfaces rate limited?

Yes. OTP send and verification, link-password checks, and public forms use per-identifier fixed-window limits backed by the database. The checks fail closed when the limiter cannot make a decision.

Are browser security headers configured?

Baseline security headers are enforced. Content Security Policy is rolling out in report-only mode before enforcement.

Infrastructure

Which providers operate the hosted service?

DocKosha uses specialist providers for database and authentication, object storage, application hosting, billing, transactional email, product analytics, and error monitoring. The current providers and data categories are listed on the subprocessor page.

What backup and disaster-recovery controls exist?

Database backups are Supabase-managed and automated. We do not claim a customer-specific recovery point or recovery time objective on this page.

How is production monitored?

Sentry provides production error monitoring with PII-scrubbed reports. Operational telemetry is kept server-side where credentials or secrets are involved.

Is document conversion sent to a remote conversion service?

DocYantra 0.0.26 handles PDF, Office, Markdown, and redaction work within its validated limits. The dependency fails closed outside its envelope; there is no provider-selection variable or fallback provider.

Incident response

Has DocKosha completed a formal third-party penetration test?

No formal third-party penetration test has been completed to date. DocKosha operates a good-faith vulnerability disclosure program under the published security policy.

How quickly are vulnerability reports acknowledged?

The disclosure policy targets acknowledgment within 3 business days and ongoing updates while a report is investigated and fixed.

How are customers notified of a data breach?

Incidents are investigated and contained using available application, database, storage, and monitoring evidence. Where customer personal data is affected, notification is made without undue delay as required by the applicable agreement and law.

Need supporting detail?

Send the missing question or your organization's review template. We will answer against the current implementation and identify anything that still needs verification.

Email the security team