Your clients trust you with sensitive documents. We take that seriously.
Current safeguards and limitations, stated plainly.
Encryption
The public DocScoop service is delivered over HTTPS. Uploaded files are served through expiring presigned URLs rather than public bucket listings. We do not currently publish an independent at-rest encryption certification or database-transport attestation.
Infrastructure
DocScoop runs on dedicated Hetzner servers in the European Union. Our infrastructure uses Docker Swarm with isolated networks, separating application servers, databases, and background workers across dedicated nodes. No shared hosting, no multi-tenant cloud functions.
Access Control
Staff API requests use JWTs verified against RS256 keys through JWKS. Product routes apply organization and role checks, while client portal access uses a scoped engagement token. A portal link grants access until it expires or is revoked and must be handled like a credential.
File Storage
Documents use MinIO-compatible object storage with non-public buckets. A valid presigned URL can be used by anyone who possesses it until its short expiry, so links should not be forwarded or placed in shared logs.
Monitoring
The hosting platform collects uptime, application-error, and infrastructure metrics. Monitoring improves incident visibility but does not guarantee that every anomaly is detected before customer impact, and DocScoop does not currently publish an uptime SLA.
Compliance
DocScoop is not currently SOC 2 certified. There is no self-service account export or deletion workflow today. Privacy requests are handled through the published contact address while product-level data-rights tooling and a formal subprocessor register are still being developed.
Report a Vulnerability
If you have security concerns or want to report a vulnerability, contact security@docscoop.com. Include the affected URL, impact, and safe reproduction details; do not include client documents or credentials in email.