Docupath is a multi-tenant document intelligence platform where each organization operates within its own isolated tenant environment at yourOrganization.docupath.app. Platform security is foundational to protecting sensitive document data - including invoices, purchase orders, contracts, medical records, and bank statements - across all tenants.
This article describes how Docupath secures tenant data through encryption, access controls, multi-tenant isolation, and compliance certifications.
When It Is Used
Platform security applies at all times across the Docupath platform. It is relevant when:
Evaluating Docupath for procurement or vendor assessments
Completing security questionnaires or compliance audits
Understanding how tenant data is separated and protected
Configuring user access and authentication for an organization
Assessing data residency requirements for EU or US storage
Inputs
Organization configuration (tenant setup, region selection)
User accounts and role assignments
SSO identity provider configuration (Google or Microsoft)
API credentials (Client ID and Secret)
Outputs
Isolated, encrypted tenant environments
Role-enforced access to platform features
Audit logs of all user and system actions
Compliance documentation and certifications
Core Functions
Multi-Tenant Isolation
Docupath uses logical data separation to ensure that each tenant's documents, extracted data, and configuration are fully isolated. No tenant can access another tenant's data. All tenant operations are scoped by organization identity.
Encryption-at-Rest
All stored data - including uploaded documents, extracted data fields, organization configuration, and audit logs - is encrypted at rest using industry-standard encryption. Storage is hosted on AWS S3 with server-side encryption enabled.
Region-Aligned Storage
Docupath supports region-aligned data storage, allowing organizations to store their data in either EU or US regions based on regulatory or business requirements.
Role-Based Access Control (RBAC)
Docupath enforces access through five built-in system roles, plus any custom roles a tenant defines. Every user holds exactly one role.
System role | Description |
Admin | Full platform configuration and user management. The only role that can manage roles, open Billing & Payments, or edit Country and Global configuration |
Manager | Operational oversight and workflow management. Cannot manage roles, open Billing & Payments, or reach the Country and Global tabs of the four per-tab configuration modules |
Reviewer | Reviews extracted document data and approves or rejects it. Can reprocess and download documents. Cannot delete documents |
Validator | Validates reviewed data before export. Can reprocess and download documents. Cannot delete documents |
Reviewer and Validator | Combined review and validation capabilities. Can reprocess and download documents. Cannot delete documents |
The four per-tab configuration modules are Instruction Builds, Transformations, Rejections and Customize Captured Fields. A manager works in all four, but only on their Organization and Trading Party tabs; changing Country and Global configuration is reserved for admins.
System roles are read-only templates that can be duplicated as the starting point for a custom role. Admins build custom roles on the Roles tab under Settings → Manage Users & Roles, granting read and write per module, and assign one role to as many users as needed. Country and Global configuration can be granted to a custom role as view access but never write, and Billing & Payments cannot be granted to a custom role at all.
The Users tab is open to anyone who can manage users, which is admins and managers. The Roles tab and role editing are available to admins only.
Access is enforced consistently rather than by hiding the product: a user sees a module only when their role can at least read it, and within a module any action their role does not allow is greyed out with an explanatory tooltip.
Single Sign-On (SSO)
Docupath supports SSO via Google and Microsoft identity providers, enabling organizations to enforce centralized authentication policies.
API Authentication
External system integrations authenticate using OAuth 2.0 Client Credentials flow, leveraging a Client ID and Client Secret pair generated within the platform.
Audit Logging
All actions within the platform - including user logins, document uploads, data modifications, and configuration changes - are recorded in audit logs for traceability and compliance.
Business Impact
Enables Docupath adoption in regulated industries handling sensitive documents
Supports compliance with data protection regulations such as GDPR
Reduces risk of unauthorized access through enforced RBAC and SSO
Provides audit trails required for internal and external audits
Common Scenarios
Scenario 1: Vendor Security Assessment
A prospective customer requests Docupath's security posture documentation. The platform's ISO 27001 certification, encryption-at-rest, multi-tenant isolation, and RBAC model are referenced to complete the security questionnaire.
Scenario 2: Configuring Access for a New Team
An Admin sets up users with appropriate roles (Reviewer, Validator) and enables SSO via Microsoft to enforce the organization's authentication policies.
Scenario 3: Compliance Audit
An organization's compliance team reviews Docupath's audit logs and encryption practices to satisfy GDPR data protection requirements.
Technical Dependencies
AWS infrastructure for encrypted storage and region-aligned hosting
Google or Microsoft identity providers for SSO
Organization and Sub Organization configuration within Docupath
Notes
SSO is limited to Google and Microsoft identity providers; custom SAML/OIDC providers are not currently supported
Region selection is configured at setup and cannot be changed after provisioning
SOC 2 certification is currently in progress and not yet completed
