DoqSeal/Security
Trust Architecture

Security isn't a checkbox. It's the architecture.

DoqSeal was designed after the DPDP Act passed. Encryption is client-side. Processing happens in enclaves. Keys live for milliseconds. We can't read your documents — and we built it that way on purpose.

SOC 2

Type II

Audited annually by Deloitte

ISO

27001 : 2022

Information security mgmt

DPDP

Section 11 Compliant

Consent receipts built-in

CERT-In

Empanelled

Auditor: ITAS Solutions

Five Pillars

What we do, and what we refuse to.

Encryption everywhere

AES-256-GCM at rest. TLS 1.3 in transit. Per-tenant data encryption keys derived via HKDF and rotated quarterly.

AES-256-GCM at restTLS 1.3 in transitHKDF-derived per-tenant keysQuarterly rotation

Zero-knowledge processing

Extraction runs inside AWS Nitro enclaves and Intel SGX TEEs. The hypervisor cannot inspect memory. Keys exist for the duration of a single request, then evaporate.

AWS Nitro enclaves (production)Intel SGX (on-prem option)Attested boot chainEphemeral session keys

India data residency

Primary in ap-south-1 (Mumbai). Disaster recovery in ap-south-2 (Hyderabad). Backups encrypted with customer-managed keys. Data never leaves Indian sovereign territory.

Mumbai · primaryHyderabad · DRBYO-KMS supportedAir-gapped on-prem (Vault Edition)

Identity & access

SSO via SAML 2.0 / OIDC. SCIM 2.0 for user provisioning. Per-document RBAC with attribute-based extensions. MFA enforced on all admin actions.

SAML / OIDC SSOSCIM 2.0 provisioningABAC + RBACStep-up MFA on writes

Auditability

Every action — upload, view, extract, export, delete — written to an append-only log signed with our HSM. Stream to your SIEM via Splunk HEC, Datadog, or syslog.

Append-only audit logHSM-signed entriesSIEM streaming7-year default retention

Disclosure & response

SLA: critical incident notification within 4 hours. Public hello@doqseal.com PGP key. Bug bounty up to ₹5L per critical CVE. Quarterly pen-tests by Bugcrowd.

4hr critical SLAPGP-published intakeBug bounty: ₹5L maxQuarterly pen-test
Sub-processors

Three vendors. All in India.

A short list, kept short on purpose. Every sub-processor signed a DPA with India-only data residency. List updated within 30 days of any change.

AWS India (Mumbai + Hyderabad)

Compute, storage, KMS. Sub-processor agreement: BAA-equivalent + DPDP addendum.

NSE India · IDEMIA

HSM operator for our root signing keys. CCA-licensed.

Sentry (self-hosted, in-VPC)

Error monitoring runs inside our infrastructure — never sends data outside India.

Read the full security whitepaper.

Detailed architecture, threat model, and audit reports are available under MNDA. Email hello@doqseal.com.