Enterprise-Grade Security

Security & Compliance

DOKit is built from the ground up for regulated industries. Your data is encrypted, isolated, and protected at every layer.

HIPAA

Compliant

AWS BAA

Signed

GDPR

Ready

256

AES-256

Encryption

How We Protect Your Data

Encryption at Rest & Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Database encryption keys are managed through AWS KMS with automatic rotation.

  • AES-256 encryption at rest
  • TLS 1.3 for all connections
  • AWS KMS key management

AWS Infrastructure

DOKit runs entirely on AWS with a signed Business Associate Agreement (BAA). All infrastructure is deployed in private subnets with no public internet exposure.

  • AWS BAA signed
  • Private VPC deployment
  • US-based data centers

Access Control

Role-based access control (RBAC) ensures users only see what they need. SSO/SAML integration available for enterprise customers.

  • Role-based permissions
  • SSO/SAML support
  • MFA enforcement

Audit Logging

Complete audit trail of all user actions, document access, and system events. Logs are retained for compliance and available for export.

  • Complete audit trail
  • Exportable reports
  • Real-time monitoring

Data Handling & Retention

Document Processing

  • Documents are processed in isolated, encrypted containers
  • AI processing uses HIPAA-compliant OpenAI endpoints
  • No document data is used for AI training

Data Retention

  • Configurable retention periods (7-90 days)
  • On-demand data deletion available
  • Zero-retention mode for sensitive workflows

Need a Business Associate Agreement?

We provide signed BAAs for all customers handling protected health information (PHI). Our BAA covers all DOKit services and underlying AWS infrastructure.

Ready to get started?

Start your 14-day free trial. No credit card required.

Contact Sales