DocSpring Logo
  • Products
    • PDF Filling API
    • PDF Generation API
    • HTML to PDF API
    • Embedded Template Editor
    • Web Forms
  • Industries
    • Real Estate
    • Legal
    • Insurance
    • Immigration
    • Accounting
  • Pricing
  • Documentation
  • Contact
    • CHAT: Open Live Chat
    • EMAIL: [email protected]
Sign In Start Free Trial
Dashboard Sign Out
Start Free Trial
  • PDF Filling API
  • PDF Generation API
  • HTML to PDF API
  • Embedded Editor
  • Web Forms
  • Documentation
  • Pricing
  • Changelog
  • API Status
  • Blog
  • Security
  • Privacy
  • DPA
  • TOS
  • GitHub
  • Twitter
Sign In Start Free Trial
Dashboard Sign Out

Security

DocSpring follows industry best-practices to keep your data safe:

  • You can only access the DocSpring service via TLS (https). We enforce this with HSTS headers.
  • Submission data stored in our database is encrypted at rest using AES-256.
  • Our Redis job queue and cache is encrypted at rest.
  • All stored files are encrypted at rest, using the AWS Key Management Service. This includes template PDFs, generated PDFs, and any other files that are stored in Amazon S3.
  • Passwords are hashed using bcrypt with 11 key expansion rounds. We do not store plaintext passwords in our database.
  • We record application, access, and administrative activity to support security monitoring and investigations.
  • Retention depends on the type of log. API and webhook database logs are subject to a 90-day deletion schedule. Lambda worker logs are retained for 30 days. Rack access logs are configured for 2,555 days (approximately seven years), while the administrative gateway is configured for 2,557 days. Database recovery copies have separate retention periods, described in our privacy policy.
  • We subscribe to security mailing lists and patch any vulnerabilities as soon as possible.

Compliance

SOC 2 Type II Audited

SOC 2 Type II

GDPR Compliant

GDPR Compliant

HIPAA Compliant

HIPAA Compliant

DocSpring has completed a SOC 2 Type II audit and is GDPR and HIPAA compliant. We are currently working towards ISO 27001 certification.

Our SOC 2 Type II report and security whitepaper are available on request from the DocSpring Trust Portal. Please contact [email protected] for any additional information.

The SOC 2 Type II report covers July 24 to October 22, 2025, for Security, Confidentiality, and Availability.

HIPAA Compliance

DocSpring is HIPAA compliant. We are happy to sign a Business Associate Agreement (BAA) with customers on request. To request a BAA, please contact [email protected].

You must sign a BAA with us before submitting any protected health information (PHI) to DocSpring.

PCI DSS

DocSpring is not PCI DSS certified. You must not submit any credit card information to DocSpring.

Vulnerability Disclosures

DocSpring welcomes vulnerability disclosures. Please send an email to [email protected] to report any security vulnerabilities. You can find our PGP public key at:
https://docspring.com/pgp-key.txt

Questions?

Any questions about security can be sent to [email protected]

Last Modified:

DocSpring Logo
Products
  • PDF Filling API
  • PDF Generation API
  • HTML to PDF API
  • Embedded Editor
  • Web Forms
Industries
  • Real Estate
  • Legal
  • Insurance
  • Immigration
  • Accounting
Resources
  • FAQ
  • Pricing
  • Changelog
  • API Status
Developers
  • Documentation
  • Template Editor
  • HTML Templates
Company
  • DocSpring Blog
  • Contact
  • GitHub
  • Twitter
Legal
  • Security
  • Trust Portal
  • Privacy
  • DPA
  • TOS
  • Cookie settings
© 2017-2026 DocSpring, Inc.
Advertisement
Advertisement