Docupath is a multi-tenant document intelligence platform where each organization operates within its own isolated tenant environment at yourOrganization.docupath.app. Platform security is foundational to protecting sensitive document data - including invoices, purchase orders, contracts, medical records, and bank statements - across all tenants.
This article describes how Docupath secures tenant data through encryption, access controls, multi-tenant isolation, and compliance certifications.
When It Is Used
Platform security applies at all times across the Docupath platform. It is relevant when:
Evaluating Docupath for procurement or vendor assessments
Completing security questionnaires or compliance audits
Understanding how tenant data is separated and protected
Configuring user access and authentication for an organization
Assessing data residency requirements for EU or US storage
Inputs
Organization configuration (tenant setup, region selection)
User accounts and role assignments
SSO identity provider configuration (Google or Microsoft)
API credentials (Client ID and Secret)
Outputs
Isolated, encrypted tenant environments
Role-enforced access to platform features
Audit logs of all user and system actions
Compliance documentation and certifications
Core Functions
Multi-Tenant Isolation
Docupath uses logical data separation to ensure that each tenant's documents, extracted data, and configuration are fully isolated. No tenant can access another tenant's data. All tenant operations are scoped by organization identity.
Encryption-at-Rest
All stored data - including uploaded documents, extracted data fields, organization configuration, and audit logs - is encrypted at rest using industry-standard encryption. Storage is hosted on AWS S3 with server-side encryption enabled across all environments.
Region-Aligned Storage
Docupath supports region-aligned data storage, allowing organizations to store their data in either EU or US regions based on regulatory or business requirements.
Role-Based Access Control (RBAC)
Docupath enforces access through six platform roles:
Role | Description |
Admin | Full platform configuration and user management |
Manager | Operational oversight and workflow management |
Reviewer | Reviews extracted document data |
Validator | Validates reviewed data before export |
Reviewer + Validator | Combined review and validation capabilities |
Custom | Customizable role with granular control over accessible features |
Single Sign-On (SSO)
Docupath supports SSO via Google and Microsoft identity providers, enabling organizations to enforce centralised authentication policies.
API Authentication
External system integrations authenticate using OAuth 2.0 Client Credentials flow, leveraging a Client ID and Client Secret pair generated within the platform by Admin users.
Audit Logging
All actions within the platform - including user logins, document uploads, data modifications, and configuration changes - are recorded in audit logs for traceability and compliance.
Business Impact
Enables Docupath adoption in regulated industries handling sensitive documents
Supports compliance with data protection regulations such as GDPR
Reduces risk of unauthorised access through enforced RBAC and SSO
Provides audit trails required for internal and external audits
Common Scenarios
Scenario 1: Vendor Security Assessment
A prospective customer requests Docupath's security posture documentation. The platform's ISO 27001 certification, encryption-at-rest, multi-tenant isolation, and RBAC model are referenced to complete the security questionnaire.
Scenario 2: Configuring Access for a New Team
An Admin sets up users with appropriate roles (Reviewer, Validator) and enables SSO via Microsoft to enforce the organization's authentication policies.
Scenario 3: Compliance Audit
An organization's compliance team reviews Docupath's audit logs and encryption practices to satisfy GDPR data protection requirements.
Technical Dependencies
AWS infrastructure for encrypted storage and region-aligned hosting
Google or Microsoft identity providers for SSO
Organization and Sub Organization configuration within Docupath
Notes
SSO is limited to Google and Microsoft identity providers; custom SAML/OIDC providers are not currently supported
Region selection is configured at setup and cannot be changed after provisioning
SOC 2 certification is currently in progress and not yet completed
