Skip to content
DocuDriver

The controls are in the database and the platform, not in the prompt.

Whatever a question says, the same rules hold. Here is what they are.

Security

The controls are in the database and the platform, not in the prompt, so they hold whatever a question says.

Isolation per workspace

Every table carries the workspace, and Postgres row-level security filters every query. A member of one workspace cannot reach another's, even through the assistant.

Sign-in protection

Two-factor authentication, required per workspace if the owner chooses; sign-in throttling and a full sign-in trail; a list of active sessions with sign out anywhere; an inactivity timeout.

Metadata only

Extraction keeps table names, fields, measures, queries, and lineage. Customer, employee, and student records are never read, stored, or sent to a model.

Audit trail and retention

Every upload, approval, grant, hold, and setting change is logged with who and when. Nothing is deleted silently, and a legal hold freezes everything under it.

Inside a workspace

Access inside a workspace

Roles, collection grants, and a hierarchy decide who can see, ask about, or download each source. The assistant retrieves only from documents the asker may read, and the rule is applied by the database before any text reaches a model.

Single sign-on and provisioning

Workspaces on the Institution plus SSO plan sign people in through their own identity provider (SAML 2.0 or OpenID Connect) and provision members from the directory (SCIM 2.0), with roles from directory groups. Owners keep a password and two-factor sign-in as a break-glass path.

Support access

DocuDriver staff cannot see inside a workspace unless the owner has allowed support access. Every support session is time-limited, has a written reason, is recorded in the workspace's own audit log, and is sent to the owners by mail.

AI models and your data

Questions and the passages used to answer them are sent to the model for the length of the request and are not used to train it. A workspace can bring its own model key, in which case nothing passes through DocuDriver's model account at all. The assistant answers from your documents first, cites what it used, and says so when it is answering from general knowledge instead. The full statement is the AI use statement.

Extraction keeps structure and metadata only: table names, fields, measures, queries, lineage, and the text of policy and procedure documents you choose to upload. Customer, employee, and student records are never read, stored, or sent to a model.

Compliance

DocuDriver is built to the HECVAT 4 and SOC 2 control sets and keeps its control status, product-supplied evidence, and accessibility results on a trust page available to customers on request. The product's policy documents are public: the Privacy notice, the AI use statement, and the Terms of service.

Questions about security, and reports of a problem, go to Terrance.Adam@gmail.com. We answer within one business day and keep you informed until the matter is closed.

Questions your security review will ask

Bring your questionnaire to the demo, or send it ahead. We answer from the trust page, not from memory.