DocSpring follows industry best-practices to keep your data safe:
SOC 2 Type II
GDPR Compliant
HIPAA Compliant
DocSpring has completed a SOC 2 Type II audit and is GDPR and HIPAA compliant. We are currently working towards ISO 27001 certification.
Our SOC 2 Type II report and security whitepaper are available on request from the DocSpring Trust Portal. Please contact [email protected] for any additional information.
DocSpring is HIPAA compliant. We are happy to sign a Business Associate Agreement (BAA) with customers on request. To request a BAA, please contact [email protected].
You must sign a BAA with us before submitting any protected health information (PHI) to DocSpring.
DocSpring is not PCI DSS certified. You must not submit any credit card information to DocSpring.
DocSpring welcomes vulnerability disclosures.
Please send an email to [email protected]
to report any security vulnerabilities.
You can find our PGP public key at:
https://docspring.com/pgp-key.txt