A clear security posture before integration starts.
Dockt processes sensitive workforce evidence inside a workspace-scoped platform. This page explains the controls in place today, the responsibilities customers retain, and the commitments that are agreed contractually.

Security starts with explicit boundaries.
The product keeps customer scope, operator access, evidence, and decision history separate and traceable throughout the assessment workflow.
EU-first infrastructure
ResidencyDockt uses EU execution and storage as the default for operational product data and canonical workforce evidence.
Scoped access
AuthorisationCredentials, configuration, assessments, and webhook endpoints are scoped to an account or workspace. Operator access is separately protected.
Encryption
ProtectionPublic interfaces use HTTPS. Managed storage provides encryption at rest, and webhook signing secrets receive application-level encryption.
Retrievable records
AuditabilityEvidence, findings, review reasons, decision metadata, and earlier decisions remain connected for later review.
What can your security team expect today?
Dockt answers these points directly during partner review and records any customer-specific commitment in the agreement.
- Data residency and international transfers
- Product execution and storage are EU-first. When a service provider processes data outside the EEA or United Kingdom, Dockt uses contractual transfer safeguards and limits the data shared to the service purpose.
- GDPR roles and lawful basis
- A customer normally acts as controller for worker and contractor data, with Dockt acting as processor under the customer agreement and data-processing agreement. Dockt acts as controller for its own website, account, security, and sales data using the lawful bases described in the privacy policy.
- Retention and deletion
- Product-data retention is defined by the customer agreement, workspace configuration, and applicable legal requirements. Dockt does not publish one universal retention period because workforce evidence obligations differ by customer and context.
- Incident response
- Suspected incidents are triaged, access is contained, affected systems and providers are reviewed, and customers are notified where the agreement or applicable law requires it. Security reports can be sent to hello@dockt.com.
- Availability commitments
- Dockt does not publish a universal uptime SLA today. Service levels, support expectations, and incident communication are agreed during customer onboarding when required.
- Certification status
- Dockt’s security management program complies with ISO/IEC 27001 requirements. External certification is in progress, and the certificate will be published when that process is complete. SOC 2 is outside the current assurance program.
Current subprocessors and service providers.
These providers support the product or website today. The data shared with each provider is limited to its operating purpose. Customer contractual terms remain the authoritative subprocessor notice for a specific deployment.
Bring your security questions into the first conversation.
Share the review requirements your team or customer uses. We’ll answer against the current architecture and document any agreed commitments.