Security & Trust Standards
Protecting your vendor certificates of insurance, policy documents, and corporate records is our top priority.
Last Updated: August 5, 2026 • Verified Standard v4.2
256-Bit AES Encryption
All certificates of insurance (COIs), tax forms, and vendor records are encrypted at rest with AES-256 and in transit using TLS 1.3.
Multi-Tenant Isolation
Strict row-level database authorization policies guarantee your compliance data is isolated and accessible only to verified team members.
Stateless AI OCR
Document parsing uses ephemeral AI sandboxes. Your private vendor contracts and COIs are NEVER used to train third-party AI models.
SOC 2 Aligned Hosting
Built on AWS and Supabase infrastructure featuring 99.9% target uptime, real-time failover replication, and automated daily backups.
1. Security Philosophy & Commitment
SubDoc provides automated Certificate of Insurance (COI) tracking, vendor compliance management, and document verification software for businesses, general contractors, and property managers.
We recognize that Certificates of Insurance, W-9 forms, endorsements, and vendor contracts contain confidential business data and personally identifiable information (PII). Our security architecture is designed following defense-in-depth principles, ensuring strict data confidentiality, integrity, and continuous availability across all service tiers.
2. Encryption Standards (Transit & Rest)
SubDoc enforces strict cryptographic encryption for all data entering, leaving, or residing within our platform:
- Encryption in Transit: All HTTP connections to SubDoc web applications, API endpoints, webhooks, and vendor upload portals are secured using TLS 1.3 (with TLS 1.2 backwards compatibility). HTTP Strict Transport Security (HSTS) is enforced to reject unencrypted traffic.
- Encryption at Rest: All stored documents (PDFs, images, compliance records) are stored in secure cloud storage buckets protected with 256-bit Advanced Encryption Standard (AES-256) server-side encryption.
- Database Encryption: PostgreSQL relational databases, indexes, and automated backups are encrypted at rest using AES-256 block ciphers with rotating master key management.
3. Multi-Tenant Data Isolation
SubDoc operates a multi-tenant cloud architecture built with strict logical boundary isolation between workspace accounts:
Every API request automatically verifies and enforces strict workspace boundaries. Cross-workspace data access or exposure between client accounts is prevented at the database and application levels.
- Strict organization scoping prevents unauthorized cross-tenant data requests.
- Public vendor upload links use single-use cryptographic tokens with configurable expiration windows.
- Broker access portals require token verification before rendering policy details or compliance statuses.
4. AI OCR Processing & Privacy Safeguards
SubDoc utilizes automated Artificial Intelligence (AI) and Optical Character Recognition (OCR) to extract key policy numbers, expiration dates, coverage limits, and insurance carrier names from uploaded COIs.
Your uploaded compliance documents and extracted policy details are processed statelessly in ephemeral compute containers. SubDoc does NOT train public or third-party AI models on your private certificates, company contracts, or vendor information.
5. Cloud Infrastructure & Resilience
Our production services are hosted on tier-one cloud providers (Vercel, Heroku, and Supabase / AWS) designed for enterprise availability and resilience:
- High Availability: Load-balanced multi-region edge deployment ensures 99.9% target uptime for web applications and vendor upload portals.
- Continuous Backups: Database state is continuously recorded with Point-in-Time Recovery (PITR) and automated daily encrypted off-site backups stored across redundant availability zones.
- DDOS & WAF Defense: Enterprise Web Application Firewalls (WAF), rate-limiting engines, and DDoS protection shield our network against automated bot traffic and brute-force attacks.
6. Authentication & Role-Based Access Control (RBAC)
Workspace security depends on strong identity verification. SubDoc provides granular access control mechanics:
- Secure Credentials: User passwords are hashed using industry-standard Bcrypt with unique salt rounds. SubDoc never stores plain-text passwords.
- Single Sign-On (SSO): Google OAuth 2.0 integration allows team members to authenticate using enterprise Google Workspace credentials.
- Role-Based Access (RBAC): Define explicit user roles within your workspace (Owner, Admin, Member) to restrict billing, document deletion, and compliance requirement configuration.
- Magic Link Authentication: Passwordless login via secure, time-limited magic links dispatched directly to authorized business email addresses.
7. Industry Standards Alignment
SubDoc operates in alignment with global data protection frameworks:
All credit card processing and billing information is handled directly by our PCI-DSS Level 1 compliant merchant of record (Paddle). SubDoc never processes or stores raw payment card numbers on our servers.
8. Vulnerability Reporting & Contact
We welcome reports from independent security researchers, customers, and partners. If you believe you have discovered a security vulnerability or potential threat within SubDoc, please report it to our security team immediately:
Email: [email protected]
Please include detailed reproduction steps, HTTP logs, or payload proofs. We promise to acknowledge security reports within 24 hours and keep you updated throughout our remediation process.