Your documents stay yours
Privacy isn't a checkbox at Docutrix — it's the reason teams trust us with their most sensitive documents.
Data Isolation
Complete tenant separation
Every organisation on Docutrix runs in its own isolated environment. Your documents, vector indexes, and query logs are never co-mingled with another customer's data.
Separate storage per tenant
Document storage buckets, vector databases, and relational stores are provisioned per tenant. There is no shared storage layer that could allow cross-tenant data access.
Isolated query pipelines
When a user asks a question, the retrieval pipeline queries only that organisation's index. There is no shared retrieval context across tenants.
Encryption
Encryption at rest — AES-256
All documents, embeddings, and metadata are encrypted at rest using AES-256. Encryption is applied at the storage layer and is transparent to users.
Encryption in transit — TLS 1.2+
All data transferred between your browser/app and Docutrix's servers is encrypted using TLS 1.2 or higher. TLS 1.0 and 1.1 are explicitly disabled.
Bring your own key (BYOK) — Enterprise
Enterprise customers can use their own encryption keys managed via AWS KMS, Azure Key Vault, or GCP Cloud KMS. Docutrix never has access to your plaintext key material.
AI & Data Usage
No training on your data
Docutrix does not use your documents, queries, or answers to train, fine-tune, or improve AI models — on any plan. This is a contractual commitment, not just a policy.
Documents used only to answer your questions
Documents are stored only to serve your queries. Docutrix does not copy, distribute, or analyse your documents for any purpose other than answering your team's questions.
Audit-logged AI usage
All AI queries are logged with timestamps, user identifiers, and document references. Enterprise plans can export these logs to your SIEM.
Access Controls
Role-based document permissions — Business & Enterprise
Admins can restrict document collections to specific users or teams. Access controls are enforced at query time — a user cannot retrieve answers from documents they are not authorised to access.
Compliance
GDPR-aligned data processing
Docutrix acts as a data processor under GDPR. Enterprise plans include a Data Processing Agreement (DPA) that covers your obligations as a data controller.
Data residency options — Enterprise
Data residency options are available for Enterprise customers. Talk to sales to discuss your requirements.
Australian Privacy Principles
Docutrix is built and operated in Australia by ZGuy Software Solutions Pty Ltd. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as set out in our Privacy Policy.
Retention & Subprocessors
Delete documents at any time
Deleting a document is immediate and permanent: it is removed from the index and can no longer be cited in answers. Admins can delete any document; members can delete the documents they uploaded.
When a subscription ends
After your subscription ends, your workspace content is deleted in line with your agreement with us. Contact us before cancelling if you need a copy of anything.
Subprocessors
We use a small number of service providers to run Docutrix: cloud hosting and storage (Microsoft Azure or Amazon Web Services, depending on your deployment), the AI model provider configured for your workspace (for example Anthropic or OpenAI — or a private model in your own environment on Enterprise), Mautic for contact and email, Google Analytics and Tag Manager for website analytics (with consent), and Cloudflare for form spam protection. Enterprise customers can request the current list with their DPA.
Private Deployment
Private hosted LLM
For organisations that cannot send document content to any third-party LLM API, Enterprise plans include the option to run the AI entirely within your own VPC. Your document content never leaves your infrastructure.
On-premise deployment
Full on-premise deployment is available for organisations with air-gapped environments or strict data sovereignty requirements. Contact our sales team to discuss requirements.
Choice of LLM
Enterprise customers can choose their preferred LLM backend — including models hosted by Anthropic, OpenAI, Mistral, or an open-source model running in your own environment.
Responsible disclosure
If you believe you have discovered a security vulnerability in Docutrix, please email security@docutrix.com with details. We commit to acknowledging your report within 24 hours.