Security, Privacy
& LGPD Compliance
Enterprise-grade security for document processing. Your data is encrypted in transit and at rest, and document images are never stored.
LGPD Compliance
Fully compliant with Brazil's General Data Protection Law
Data Minimization
We collect and process only the minimum data necessary for document extraction. No unnecessary data retention.
Lawful Basis
Each processing of personal data has its legal basis under the LGPD, set out in our Privacy Policy.
Right to Deletion
Document images are deleted after processing, and an extraction's answer within 15 minutes. Users can request deletion of account data at any time.
Data Portability
Export your data in standard formats at any time through the admin dashboard.
Data Protection Officer (DPO)
Our data protection officer is Idalio Pessoa, available at dpo@docsocr.com for privacy questions and data subject requests.
Data Encryption
Protection in transit and at rest for your documents
TLS 1.2+ in Transit
All API communication is encrypted with TLS 1.2 or 1.3.
Encryption at Rest
All stored data is encrypted at rest using industry-standard AES-256 encryption.
API Key Security
API keys are checked against a bcrypt hash and kept encrypted with AES-256-GCM, so you can reveal them in the dashboard. They are never stored in plaintext.
No Plaintext Logs
Sensitive data is never written to logs. API keys and document content are masked in all logging.
Infrastructure
Servers and database in Brazil
Servers in Brazil
Our servers and database are in Brazil, and images may be processed by partners outside Brazil. Sign-in, payments and site analytics use services outside Brazil.
Network Isolation
Application services run in isolated network environments with strict firewall rules.
Database Backups
We back up the database at every system update.
Monitoring & Alerts
24/7 infrastructure monitoring with automated alerts for anomalies and security events.
Data Retention
Clear policies for how we handle your data
Real-Time Processing
Document images are processed in real-time and are not stored after extraction is complete.
No Image Storage
We do not store uploaded document images. The extracted data is returned to you, and kept encrypted for up to 15 minutes only to return it again if you repeat the same request, then deleted.
Request Logs
API request metadata (timestamps, status codes, your requestId) is retained for 90 days for debugging and analytics.
Account Data
Account information is retained while your account is active and deleted upon request.
Access Controls
Granular permissions for your team
API Key Authentication
Every API request requires a valid API key. Keys are scoped to workspaces for isolation.
Workspace Isolation
Workspaces provide logical separation for teams, environments, or projects within an organization.
Role-Based Access
Organization members have defined roles (owner, admin, member and viewer) with appropriate permission levels.
Audit Trail
All administrative actions and API key operations are logged for accountability and compliance.
Questions about security?
Our team is ready to discuss your compliance requirements.