Everything a security reviewer, legal team, or enterprise buyer needs about DocuJSON — in one place. If something is missing, email us.
A layered security program covering infrastructure, application code, authentication, data handling, and vendor management.
Our Privacy Policy covers what we collect, why, who we share it with, and how long we keep it.
Available for all paid customers. Standard DPA below. Request a counter-signed copy via email.
Public list of the third-party services that process your data. 30-day change notification commitment.
| Standard | Status |
|---|---|
| SOC 2 Type I | Planned / readiness prep |
| SOC 2 Type II | On roadmap |
| HIPAA | On roadmap — do not submit PHI |
| ISO 27001 | Evaluating |
| CCPA / CPRA | Drafted — validation pending |
| GDPR / UK GDPR / Swiss FADP | Drafted — validation pending |
| PCI DSS | N/A — Stripe handles card data |
We don't sell or share personal data with advertisers or data brokers.
We don't use Customer Content to train generative AI models.
We don't grant employees unrestricted access to production customer data.
We don't claim certifications we have not achieved.
We don't hide pricing behind a “contact sales” form.
We don't auto-enroll you in paid plans without a clear checkout step.
| Document | Status |
|---|---|
| Terms of Service | In progress |
| Privacy Policy | In progress |
| Data Processing Addendum | Available on request |
| Acceptable Use Policy | In progress |
| Cookie Policy | In progress |
| Sub-processor List | In progress |
| Service Level Agreement | Per plan |
| Security | Live |
We're happy to complete CAIQ, SIG Lite, or custom vendor-risk questionnaires for Business and Enterprise customers. Turnaround: 5-10 business days for the first one, faster for updates.
On-site audits available for Enterprise with 60 days' notice, per DPA Section 11.
Security researchers — we welcome reports.
Bug bounty program planned post-SOC 2.