Skip to main content

Platform Security

How Docupath protects tenant data through encryption, access controls, multi-tenant isolation, and compliance certifications

Docupath is a multi-tenant document intelligence platform where each organization operates within its own isolated tenant environment at yourOrganization.docupath.app. Platform security is foundational to protecting sensitive document data - including invoices, purchase orders, contracts, medical records, and bank statements - across all tenants.

This article describes how Docupath secures tenant data through encryption, access controls, multi-tenant isolation, and compliance certifications.


When It Is Used

Platform security applies at all times across the Docupath platform. It is relevant when:

  • Evaluating Docupath for procurement or vendor assessments

  • Completing security questionnaires or compliance audits

  • Understanding how tenant data is separated and protected

  • Configuring user access and authentication for an organization

  • Assessing data residency requirements for EU or US storage


Inputs

  • Organization configuration (tenant setup, region selection)

  • User accounts and role assignments

  • SSO identity provider configuration (Google or Microsoft)

  • API credentials (Client ID and Secret)


Outputs

  • Isolated, encrypted tenant environments

  • Role-enforced access to platform features

  • Audit logs of all user and system actions

  • Compliance documentation and certifications


Core Functions

Multi-Tenant Isolation

Docupath uses logical data separation to ensure that each tenant's documents, extracted data, and configuration are fully isolated. No tenant can access another tenant's data. All tenant operations are scoped by organization identity.

Encryption-at-Rest

All stored data - including uploaded documents, extracted data fields, organization configuration, and audit logs - is encrypted at rest using industry-standard encryption. Storage is hosted on AWS S3 with server-side encryption enabled.

Region-Aligned Storage

Docupath supports region-aligned data storage, allowing organizations to store their data in either EU or US regions based on regulatory or business requirements.

Role-Based Access Control (RBAC)

Docupath enforces access through five built-in system roles, plus any custom roles a tenant defines. Every user holds exactly one role.

System role

Description

Admin

Full platform configuration and user management. The only role that can manage roles, open Billing & Payments, or edit Country and Global configuration

Manager

Operational oversight and workflow management. Cannot manage roles, open Billing & Payments, or reach the Country and Global tabs of the four per-tab configuration modules

Reviewer

Reviews extracted document data and approves or rejects it. Can reprocess and download documents. Cannot delete documents

Validator

Validates reviewed data before export. Can reprocess and download documents. Cannot delete documents

Reviewer and Validator

Combined review and validation capabilities. Can reprocess and download documents. Cannot delete documents

The four per-tab configuration modules are Instruction Builds, Transformations, Rejections and Customize Captured Fields. A manager works in all four, but only on their Organization and Trading Party tabs; changing Country and Global configuration is reserved for admins.

System roles are read-only templates that can be duplicated as the starting point for a custom role. Admins build custom roles on the Roles tab under Settings → Manage Users & Roles, granting read and write per module, and assign one role to as many users as needed. Country and Global configuration can be granted to a custom role as view access but never write, and Billing & Payments cannot be granted to a custom role at all.

The Users tab is open to anyone who can manage users, which is admins and managers. The Roles tab and role editing are available to admins only.

Access is enforced consistently rather than by hiding the product: a user sees a module only when their role can at least read it, and within a module any action their role does not allow is greyed out with an explanatory tooltip.

Single Sign-On (SSO)

Docupath supports SSO via Google and Microsoft identity providers, enabling organizations to enforce centralized authentication policies.

API Authentication

External system integrations authenticate using OAuth 2.0 Client Credentials flow, leveraging a Client ID and Client Secret pair generated within the platform.

Audit Logging

All actions within the platform - including user logins, document uploads, data modifications, and configuration changes - are recorded in audit logs for traceability and compliance.


Business Impact

  • Enables Docupath adoption in regulated industries handling sensitive documents

  • Supports compliance with data protection regulations such as GDPR

  • Reduces risk of unauthorized access through enforced RBAC and SSO

  • Provides audit trails required for internal and external audits


Common Scenarios

Scenario 1: Vendor Security Assessment

A prospective customer requests Docupath's security posture documentation. The platform's ISO 27001 certification, encryption-at-rest, multi-tenant isolation, and RBAC model are referenced to complete the security questionnaire.

Scenario 2: Configuring Access for a New Team

An Admin sets up users with appropriate roles (Reviewer, Validator) and enables SSO via Microsoft to enforce the organization's authentication policies.

Scenario 3: Compliance Audit

An organization's compliance team reviews Docupath's audit logs and encryption practices to satisfy GDPR data protection requirements.


Technical Dependencies

  • AWS infrastructure for encrypted storage and region-aligned hosting

  • Google or Microsoft identity providers for SSO

  • Organization and Sub Organization configuration within Docupath


Notes

  • SSO is limited to Google and Microsoft identity providers; custom SAML/OIDC providers are not currently supported

  • Region selection is configured at setup and cannot be changed after provisioning

  • SOC 2 certification is currently in progress and not yet completed

Did this answer your question?