Your documents are the whole business.
Privileged material, under a duty of confidentiality, often under a protective order. Here is exactly how it is handled, in the detail your security reviewer is going to ask for anyway.
Your documents never train a model
Not ours, not a vendor's. No customer content enters any training set, fine-tune, or evaluation corpus. This is contractual, not a setting you have to find and switch off.
Encrypted in transit and at rest
TLS 1.3 on the wire, AES-256 at rest, with per-tenant keys. Enterprise customers can bring their own key through AWS KMS and revoke it independently of us.
Tenant isolation
Logical isolation at the storage and index layer on all plans, so no query can cross a tenant boundary. Enterprise adds single tenant or in-VPC deployment where the data never leaves your account.
Data residency
US on all plans. EU on Practice and above, UK on Enterprise. Processing and storage both stay in region, including the model inference step.
Retention you control
Set retention per matter, from delete-on-completion to a fixed schedule matching your records policy. Deletion is hard deletion with a certificate, not a hidden flag.
Access controls
SAML SSO, Entra ID, SCIM provisioning, matter-level permissions, and ethical wall support so a conflicted team cannot see a matter even by direct link.
Immutable audit log
Every ingestion, agent step, model version, prompt, output, human override, export, and permission change, written append-only and exportable to your SIEM.
Subprocessors, published
The current list is on the DPA with 30 days notice before any change. Enterprise customers can veto a subprocessor and be moved to an alternative path.
What we hold, with the scope attached.
A badge without a scope statement is decoration. Each certificate below lists the legal entity, the systems in scope, and the certification body. Reports and certificates are available under NDA through the trust portal.
SOC 2 Type II
CertifiedSecurity, availability, confidentiality, and processing integrity. Twelve month observation window with no exceptions noted, including AI-specific controls for model access and output logging.
Auditor Schellman · Renewed annually · Report under NDAISO/IEC 27001:2022
CertifiedInformation security management across the platform, corporate systems, and the software development lifecycle. Surveillance audits annually, full recertification every three years.
Cert 27001-DL-2026 · Accredited by UKAS · Scope covers all production regionsISO/IEC 42001:2023
CertifiedAI management system. Covers AI system inventory, risk classification, human oversight design, training data governance, model change control, and incident handling for every agent in the product.
Cert 42001-DL-2026 · Scope includes extraction, review, and verification agentsISO/IEC 27701:2019
CertifiedPrivacy information management extension to our 27001 system, covering our role as processor for customer document content and controller for account data.
Assessed alongside ISO 27001 · Supports GDPR Article 28 obligationsSOC 3
PublishedPublic summary of the SOC 2 Type II examination. Downloadable without an NDA if you need something to attach to an internal approval before legal gets involved.
Available on the trust portal · No NDA requiredGDPR and UK GDPR
CompliantDPA with standard contractual clauses and the UK addendum, EU representative appointed under Article 27, records of processing maintained, DPIA template supplied on request.
EU and UK data residency available · Subprocessor list on the DPACCPA and CPRA
CompliantService provider under the CCPA. We do not sell or share personal information, and contractual restrictions on secondary use are written into the standard agreement.
California resident requests routed through your adminEU AI Act
AlignedDocumented system purpose, risk classification, human oversight design, logging, and transparency disclosures meeting the obligations that apply to our classification. Conformity documentation available for your own assessment.
Aligned to the August 2026 obligations · Reviewed quarterlyNIST AI RMF
MappedControls mapped to the Govern, Map, Measure, and Manage functions. Useful if your own AI governance program is built on the framework and you need a crosswalk for your risk register.
Crosswalk to ISO 42001 controls availableHIPAA
BAA availableFor healthcare litigation and any matter where PHI lands in the document set. Business associate agreement executed on request, with the technical safeguards covered under our 27001 scope.
Enterprise plans · BAA required before PHI uploadPenetration testing
AnnualThird-party network, application, and AI-specific red team testing covering prompt injection, document-borne instruction attacks, and cross-tenant retrieval. Executive summary shared with customers.
Last test Q2 2026 · Continuous automated scanning between testsCSA STAR Level 1
RegisteredCompleted CAIQ published to the Cloud Security Alliance registry. If your questionnaire is CAIQ-based, most of it is already answered before you send it.
CAIQ v4 · Public registry entryCertificates, SOC reports, the CAIQ, and the current subprocessor list live in the trust portal. Access is granted within one business day of an NDA. Vulnerability reports go to security@doculightning.com and are acknowledged within one business day.
The ones that come up in every review.
Which model providers do you use, and do they see our documents?
We run a mix of self-hosted open-weight extraction models and commercial frontier models under zero-retention enterprise agreements. Providers process content transiently to return a response and retain nothing. The current list sits in the DPA, and Enterprise customers can restrict processing to the self-hosted path only.
Can DocuLightning staff read our documents?
No, not by default. Production access requires an explicit, time-boxed grant from a customer administrator, is limited to named engineers, and every session is logged in your audit trail. There is no standing internal access to customer content.
What happens to our data if we cancel?
Export everything, including the audit log, for 30 days after termination. After that it is hard deleted on the schedule in your contract, and we issue a deletion certificate. Backups roll off within 35 days.
How do you handle a protective order or a clawback?
Matter-level isolation, ethical walls, and per-matter retention rules. Documents can be purged from a matter and its index on demand, with the purge itself recorded so you can show what was removed and when.
Where do you sit on the hallucination problem?
Two places. First, findings are grounded in retrieved passages with coordinates, so an assertion without a source cannot be rendered. Second, a verification pass re-checks each citation against the source page before delivery, and anything that fails is escalated rather than shipped. This lowers the rate, it does not eliminate it, which is why every finding is presented for human sign-off.
Send us your security questionnaire.
Most come back inside three business days. We can also start from a completed CAIQ or SIG Lite if that is faster for your team.