Skip to main content

Encryption-at-Rest

How Docupath encrypts stored data at rest to protect documents, extracted data, and configuration across all tenants

All data stored in Docupath is encrypted at rest. This includes uploaded documents, extracted data fields, organization configuration, and audit logs. Encryption is applied automatically across all tenants with no user configuration required.

How It Works

Docupath stores all uploaded documents and other tenant data on AWS infrastructure, with server-side encryption enabled. The following data types are encrypted at rest:

  • Uploaded documents - all files submitted via the UI or API (invoices, POs, contracts, medical records, bank statements, and other supported document types)

  • Extracted data - all structured data produced by the AI Model Garden during document processing

  • Organization configuration - tenant settings, business rules (Instruction Builds, Transformations, Rejection Rules), and scope configurations

  • Audit logs - records of all user and system actions within the platform

Encryption uses industry-standard algorithms and is managed at the infrastructure level. Encryption keys are handled by AWS and are not exposed to tenants or Docupath application code.


Notes

  • Encryption-at-rest is always on and cannot be disabled

  • Applies uniformly to all tenants regardless of plan or region

  • Works in conjunction with region-aligned storage (EU/US) to meet data residency requirements

  • Encryption-at-rest is one component of Docupath's broader security posture, which includes RBAC, SSO, API authentication, and audit logging

Did this answer your question?