SECURITY & COMPLIANCE

Document security, built in by design.

AES-256 encryption at rest, data residency in your region, and a complete tamper-evident audit trail on every plan. Abscode DMS organises your documents as records and keeps them protected, so your data stays yours. Built for DPDP and POPIA.

HOW WE PROTECT YOUR DATA

A defence-in-depth approach

Encryption at rest and in transit

Every record is encrypted at rest with AES-256 and protected in transit with TLS 1.2+. Keys and secrets are handled under strict controls.

Access control and single sign-on

Role-based access, least-privilege permissions, multi-factor authentication (MFA/2FA), and single sign-on with Google or Microsoft. Maker-checker approval runs natively as part of the workflow engine.

Complete tamper-evident audit trail

Every action on a record is logged and tamper-evident, so you can prove who created, edited, viewed, or approved each document, with tunable retention.

No lock-in

Export your records at any time in standard, open formats such as PDF and CSV, with original files preserved, so you are never locked in.

Bring your own storage

For Enterprise, bring-your-own-storage so records live in your Google Drive, OneDrive, S3, Azure, or NAS. You retain control of data location and ownership.

Data residency in your region

Your records are hosted in your region, India, Africa, or the US, so you can meet data residency and sovereignty requirements without extra effort.

REGULATORY ALIGNMENT

Built for compliance readiness

Abscode DMS is built to help you meet your obligations across regions. Our alignment with the major data-protection and industry frameworks is summarised below.

Is Abscode DMS aligned with India's DPDP Act 2023?
Yes. Notice-and-consent handling, purpose limitation, and support for Data Principal rights under India's Digital Personal Data Protection Act, backed by data residency in India.
Does Abscode DMS support POPIA compliance in South Africa?
Yes. Processing is aligned to POPIA's lawful-processing conditions, with operator agreements and data-subject request support.
Is Abscode DMS built for GDPR and UK GDPR?
Yes. Data-processing controls, purpose limitation, and support for data-subject rights align with the EU GDPR and UK GDPR, backed by regional data residency and a Data Processing Agreement.
Which industry frameworks does Abscode DMS support?
Records, a tamper-evident audit trail, and tunable retention that support ISO 9001, RBI Master Direction, NABH, and GST requirements, with approval workflows that run natively as part of the workflow engine.
Is Abscode DMS SOC 2 or ISO 27001 certified?
Not yet. SOC 2 and ISO 27001 are on our roadmap; Abscode DMS is not currently certified against them. We are happy to share our current control set on request.

Security controls such as maker-checker, multi-factor authentication, and multi-level approvals are available by plan; see our usage-based pricing for what each tier includes.

Sub-processors

We use a small number of vetted sub-processors under data-protection contracts (cloud hosting, email/notification delivery, and payment processing: Razorpay for India, Stripe elsewhere). A current list is available on request.

Data Processing Agreement (DPA)

A DPA is available to customers. Request it at privacy@abscode.com.

Report a vulnerability

We welcome responsible disclosure. If you believe you have found a security issue, email security@abscode.com. Please do not publicly disclose until we have responded. For confirmed personal-data breaches, we notify affected customers and authorities as required by DPDP and POPIA timelines.

Read our Privacy Policy