Your documents stay yours

Privacy isn't a checkbox at Docutrix — it's the reason teams trust us with their most sensitive documents.

Data isolation
Per-tenant infrastructure
No training on your data
Contractually guaranteed
AES-256 encryption
At rest and in transit
Private LLM option
Enterprise — your VPC

Data Isolation

Complete tenant separation

Every organisation on Docutrix runs in its own isolated environment. Your documents, vector indexes, and query logs are never co-mingled with another customer's data.

Separate storage per tenant

Document storage buckets, vector databases, and relational stores are provisioned per tenant. There is no shared storage layer that could allow cross-tenant data access.

Isolated query pipelines

When a user asks a question, the retrieval pipeline queries only that organisation's index. There is no shared retrieval context across tenants.

Encryption

Encryption at rest — AES-256

All documents, embeddings, and metadata are encrypted at rest using AES-256. Encryption is applied at the storage layer and is transparent to users.

Encryption in transit — TLS 1.2+

All data transferred between your browser/app and Docutrix's servers is encrypted using TLS 1.2 or higher. TLS 1.0 and 1.1 are explicitly disabled.

Bring your own key (BYOK) — Enterprise

Enterprise customers can use their own encryption keys managed via AWS KMS, Azure Key Vault, or GCP Cloud KMS. Docutrix never has access to your plaintext key material.

AI & Data Usage

No training on your data

Docutrix does not use your documents, queries, or answers to train, fine-tune, or improve AI models — on any plan. This is a contractual commitment, not just a policy.

Documents used only to answer your questions

Documents are stored only to serve your queries. Docutrix does not copy, distribute, or analyse your documents for any purpose other than answering your team's questions.

Audit-logged AI usage

All AI queries are logged with timestamps, user identifiers, and document references. Enterprise plans can export these logs to your SIEM.

Access Controls

Role-based document permissions — Business & Enterprise

Admins can restrict document collections to specific users or teams. Access controls are enforced at query time — a user cannot retrieve answers from documents they are not authorised to access.

Compliance

GDPR-aligned data processing

Docutrix acts as a data processor under GDPR. Enterprise plans include a Data Processing Agreement (DPA) that covers your obligations as a data controller.

Data residency options — Enterprise

Data residency options are available for Enterprise customers. Talk to sales to discuss your requirements.

Australian Privacy Principles

Docutrix is built and operated in Australia by ZGuy Software Solutions Pty Ltd. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as set out in our Privacy Policy.

Retention & Subprocessors

Delete documents at any time

Deleting a document is immediate and permanent: it is removed from the index and can no longer be cited in answers. Admins can delete any document; members can delete the documents they uploaded.

When a subscription ends

After your subscription ends, your workspace content is deleted in line with your agreement with us. Contact us before cancelling if you need a copy of anything.

Subprocessors

We use a small number of service providers to run Docutrix: cloud hosting and storage (Microsoft Azure or Amazon Web Services, depending on your deployment), the AI model provider configured for your workspace (for example Anthropic or OpenAI — or a private model in your own environment on Enterprise), Mautic for contact and email, Google Analytics and Tag Manager for website analytics (with consent), and Cloudflare for form spam protection. Enterprise customers can request the current list with their DPA.

Private Deployment

Private hosted LLM

For organisations that cannot send document content to any third-party LLM API, Enterprise plans include the option to run the AI entirely within your own VPC. Your document content never leaves your infrastructure.

On-premise deployment

Full on-premise deployment is available for organisations with air-gapped environments or strict data sovereignty requirements. Contact our sales team to discuss requirements.

Choice of LLM

Enterprise customers can choose their preferred LLM backend — including models hosted by Anthropic, OpenAI, Mistral, or an open-source model running in your own environment.

Responsible disclosure

If you believe you have discovered a security vulnerability in Docutrix, please email security@docutrix.com with details. We commit to acknowledging your report within 24 hours.