Data Storage and Security
Where your documents are stored, how they're protected, and how to control data retention
Where your documents are stored
All documents uploaded to DocuPipe are stored on AWS (Amazon Web Services) cloud infrastructure. By default, data is hosted in the US East region.
If your organization requires data residency in another region, you can change it yourself on any paid plan: go to Settings, open the General tab, and pick your region under Storage Region. The available regions are US, Europe, Canada, and Australia.
Set your region before you upload anything you care about. The region applies to new uploads only - documents you already uploaded stay in the region they were originally written to.
Encryption
- At rest - all files stored in AWS S3 are encrypted at rest
- In transit - all communication between your browser/API client and DocuPipe uses TLS (HTTPS)
Compliance certifications
DocuPipe holds the following certifications and compliance standards:
| Certification | Status |
|---|---|
| SOC 2 Type II | Certified |
| ISO 27001 | Certified |
| HIPAA | Compliant |
| GDPR | Compliant (with EU infrastructure option) |
For more details, visit our security page or trust center.
DocuPipe can execute a BAA (Business Associate Agreement) for customers handling protected health information. Contact us to get one in place.
Controlling data retention
By default, your data is stored indefinitely. DocuPipe offers two ways to control how long your data is kept:
API-driven deletion (all plans)
The API exposes deletion endpoints for documents, extractions, and jobs. You can download your results and immediately delete everything, achieving true zero data retention. This is available on every plan, including free accounts.
Automatic retention policies (paid plans)
On paid subscription plans, you can set an automatic data retention policy from Settings. Choose from 1, 3, 7, or 30 days. A background process automatically purges documents, extractions, and jobs older than your configured retention period.
Need true zero data retention? Use the API deletion endpoints to remove data immediately after downloading results. Several customers already operate this way in production.
On-premise deployment
For organizations that require full data sovereignty, DocuPipe offers an on-premise deployment option where the entire system runs within your own infrastructure. Contact us to learn more.
On-premise deployments require a minimum annual credit purchase. Reach out to discuss pricing and requirements.
Updated 21 days ago
