Skip to main content

Platform Security

How Docupath protects tenant data through encryption, access controls, multi-tenant isolation, and compliance certifications

Docupath is a multi-tenant document intelligence platform where each organization operates within its own isolated tenant environment at yourOrganization.docupath.app. Platform security is foundational to protecting sensitive document data - including invoices, purchase orders, contracts, medical records, and bank statements - across all tenants.

This article describes how Docupath secures tenant data through encryption, access controls, multi-tenant isolation, and compliance certifications.


When It Is Used

Platform security applies at all times across the Docupath platform. It is relevant when:

  • Evaluating Docupath for procurement or vendor assessments

  • Completing security questionnaires or compliance audits

  • Understanding how tenant data is separated and protected

  • Configuring user access and authentication for an organization

  • Assessing data residency requirements for EU or US storage


Inputs

  • Organization configuration (tenant setup, region selection)

  • User accounts and role assignments

  • SSO identity provider configuration (Google or Microsoft)

  • API credentials (Client ID and Secret)


Outputs

  • Isolated, encrypted tenant environments

  • Role-enforced access to platform features

  • Audit logs of all user and system actions

  • Compliance documentation and certifications


Core Functions

Multi-Tenant Isolation

Docupath uses logical data separation to ensure that each tenant's documents, extracted data, and configuration are fully isolated. No tenant can access another tenant's data. All tenant operations are scoped by organization identity.

Encryption-at-Rest

All stored data - including uploaded documents, extracted data fields, organization configuration, and audit logs - is encrypted at rest using industry-standard encryption. Storage is hosted on AWS S3 with server-side encryption enabled across all environments.

Region-Aligned Storage

Docupath supports region-aligned data storage, allowing organizations to store their data in either EU or US regions based on regulatory or business requirements.

Role-Based Access Control (RBAC)

Docupath enforces access through six platform roles:

Role

Description

Admin

Full platform configuration and user management

Manager

Operational oversight and workflow management

Reviewer

Reviews extracted document data

Validator

Validates reviewed data before export

Reviewer + Validator

Combined review and validation capabilities

Custom

Customizable role with granular control over accessible features

Single Sign-On (SSO)

Docupath supports SSO via Google and Microsoft identity providers, enabling organizations to enforce centralised authentication policies.

API Authentication

External system integrations authenticate using OAuth 2.0 Client Credentials flow, leveraging a Client ID and Client Secret pair generated within the platform by Admin users.

Audit Logging

All actions within the platform - including user logins, document uploads, data modifications, and configuration changes - are recorded in audit logs for traceability and compliance.


Business Impact

  • Enables Docupath adoption in regulated industries handling sensitive documents

  • Supports compliance with data protection regulations such as GDPR

  • Reduces risk of unauthorised access through enforced RBAC and SSO

  • Provides audit trails required for internal and external audits


Common Scenarios

Scenario 1: Vendor Security Assessment

A prospective customer requests Docupath's security posture documentation. The platform's ISO 27001 certification, encryption-at-rest, multi-tenant isolation, and RBAC model are referenced to complete the security questionnaire.

Scenario 2: Configuring Access for a New Team

An Admin sets up users with appropriate roles (Reviewer, Validator) and enables SSO via Microsoft to enforce the organization's authentication policies.

Scenario 3: Compliance Audit

An organization's compliance team reviews Docupath's audit logs and encryption practices to satisfy GDPR data protection requirements.


Technical Dependencies

  • AWS infrastructure for encrypted storage and region-aligned hosting

  • Google or Microsoft identity providers for SSO

  • Organization and Sub Organization configuration within Docupath


Notes

  • SSO is limited to Google and Microsoft identity providers; custom SAML/OIDC providers are not currently supported

  • Region selection is configured at setup and cannot be changed after provisioning

  • SOC 2 certification is currently in progress and not yet completed

Did this answer your question?