Know where your data goes. And how it is protected.
Dockt processes sensitive workforce evidence inside a workspace-scoped platform. Here are the controls in place today, the responsibilities customers retain, and the commitments agreed contractually.

Clear boundaries. Practical controls.
Customer scope, operator access, evidence, and decision history stay separate and traceable throughout the assessment workflow.
EU-first infrastructure
ResidencyDockt uses EU execution and storage as the default for operational product data and canonical workforce evidence.
Scoped access
AuthorisationCredentials, configuration, assessments, and webhook endpoints are scoped to an account or workspace. Operator access is separately protected.
Encryption
ProtectionPublic interfaces use HTTPS. Managed storage provides encryption at rest, and webhook signing secrets receive application-level encryption.
Retrievable records
AuditabilityEvidence, findings, review reasons, decision metadata, and earlier decisions remain connected for later review.
What your security team can expect today.
We answer these points directly during partner review and record customer-specific commitments in the agreement.
- Data residency and international transfers
- Product execution and storage are EU-first. When a service provider processes data outside the EEA or United Kingdom, Dockt uses contractual transfer safeguards and limits the data shared to the service purpose.
- GDPR roles and lawful basis
- A customer normally acts as controller for worker and contractor data, with Dockt acting as processor under the customer agreement and data-processing agreement. Dockt acts as controller for its own website, account, security, and sales data using the lawful bases described in the privacy policy.
- Retention and deletion
- Product-data retention is defined by the customer agreement, workspace configuration, and applicable legal requirements. Dockt does not publish one universal retention period because workforce evidence obligations differ by customer and context.
- Incident response
- Suspected incidents are triaged, access is contained, affected systems and providers are reviewed, and customers are notified where the agreement or applicable law requires it. Security reports can be sent to hello@dockt.com.
- Availability commitments
- Dockt does not publish a universal uptime SLA today. Service levels, support expectations, and incident communication are agreed during customer onboarding when required.
- Certification status
- Dockt’s security management program complies with ISO/IEC 27001 requirements. External certification is in progress, and the certificate will be published when that process is complete. SOC 2 is outside the current assurance program.
The services behind Dockt.
These providers support the product or website today. Data is limited to each service purpose. Customer terms remain the authoritative subprocessor notice for a specific deployment.
Start the security review. Bring your own questions.
Share the requirements your team or customer uses. We’ll answer against the current architecture and document agreed commitments.