docubend

How your documents are handled.

What happens to a document here, in plain words. For the whole trace of what happens to a file, down to the requests your browser makes, read this — it shows you how to check every line of it yourself.

Security

In transit
HTTPS for the whole site and the whole API.
At rest
Documents you save are stored encrypted with AES-256, with the key held apart from the database.
Your account
Passwords are stored as a PBKDF2 digest. Two-factor authentication is available on Pro and Enterprise, and enrolment is confirmed with a real code from your app before it is enforced.
Your second factor is yours
It belongs to the person, and it is turned on and off from your own account.
API credentials
OAuth 2.0 client credentials that you create and revoke yourself, scoped to read, write or both. The secret is shown once, at the moment you make it; what is stored is a digest.
Most free work stays in your browser
Fourteen of the sixteen free tools do all their work in your own tab. Password protect a PDF and Unlock a PDF use the server, because real PDF encryption needs one — both say so in their first paragraph, and the temporary copy is deleted the moment the result comes back.

Data handling

What is kept
The documents you choose to save, and their versions. On the free tier the work happens in your own browser, so the file stays on your computer.
What it is used for
Giving you your own documents back, and that is the whole of it. They stay yours.
Deletion
A deleted document goes to a bin for thirty days and is then gone. Closing your account takes everything with it.
Backups
Taken nightly, and a backup of an encrypted document is encrypted too.
Getting your work out
Everything is downloadable at any time, and reading stays open: an account whose subscription has ended can still reach and download everything it has.
Payment details
Handled by Stripe. Card details go straight to Stripe.

The formal version is the privacy notice, and the terms are here.

The record, and who can reach a document

What docubend keeps, so that “what happened to this document?” has an answer.

Every version, per document
What changed, who changed it, when, and the document exactly as it stood before. Consecutive edits by one person fold into a single entry, so the record reads as work.
Restoring is itself a version
Going back to an earlier state is recorded as a change of its own, so the whole history stays intact.
Made by a person or by your software
A change through the API is attributed to the account whose credential made it, in the same history as a change somebody made by hand.
Sharing is per person and revocable
Each person gets their own link, and any one of them can be withdrawn without disturbing the rest.
Redaction takes the words out
When text is redacted it comes out of the file, and every earlier version that held it is destroyed with it. The product tells you how many earlier versions it destroyed.
For a team
Seats you manage, central billing, volume pricing, a data processing agreement, a named person to contact, single sign-on through your own identity provider and an organisation-wide audit log are part of an Enterprise agreement. The last two are set up with you as part of that agreement.

Ask us anything about this.

If you need to know exactly where your documents go, or how a particular requirement would be met, ask and we will tell you.

Ask a question Read the whole trace Privacy notice