SECURITY & COMPLIANCE

Document security, built in by design.

AES-256 encryption at rest, data residency in your region, a complete tamper-evident audit trail, and backup and restore on every plan. Abscode DMS organises your documents as records and keeps them protected, so your data stays yours, designed to support your DPDP, POPIA, and GDPR obligations.

HOW WE PROTECT YOUR DATA

A defence-in-depth approach

Encryption at rest and in transit

Every record is encrypted at rest with AES-256 and protected in transit with TLS 1.2+. Keys and secrets are handled under strict controls.

Access control and single sign-on

Role-based access, least-privilege permissions, and single sign-on with Google or Microsoft. Approval is optional, so you turn on maker-checker only where you need it.

Complete tamper-evident audit trail

Every action on a record is logged and tamper-evident, so you can prove who created, edited, viewed, or approved each document, with tunable retention.

Backup, restore, and no lock-in

Encrypted backup and restore are included on every plan, free tier included. Export your records at any time in standard formats, so you are never locked in.

Enterprise resilience

For Enterprise, add multi-region high availability and disaster recovery with custom RTO/RPO, plus bring-your-own-storage so records live in your Google Drive, OneDrive, S3, Azure, or NAS.

Data residency in your region

Your records are hosted in your region, India, Africa, or the US, so you can meet data residency and sovereignty requirements without extra effort.

REGULATORY ALIGNMENT

Built for compliance readiness

Abscode DMS is built to help you meet your obligations across regions. Our alignment with the major data-protection and industry frameworks is summarised below.

GDPR & UK GDPR (Europe / UK)
Designed to support your GDPR / UK GDPR obligations, with support for data-subject rights and breach notification. A Data Processing Agreement is available on request.
DPDP Act 2023 (India)
Notice-and-consent handling, purpose limitation, and support for Data Principal rights under India's Digital Personal Data Protection Act, backed by data residency in India.
POPIA (South Africa)
Processing aligned to POPIA's lawful-processing conditions, with operator agreements and data-subject request support.
Industry frameworks
Records, tamper-evident audit trail, and tunable retention that support ISO 9001, RBI Master Direction, NABH, and GST requirements, with optional approval where your process calls for it.

Sub-processors

We use a small number of vetted sub-processors under data-protection contracts (cloud hosting, email/notification delivery, and payment processing: Razorpay for India, Stripe elsewhere). A current list is available on request.

Data Processing Agreement (DPA)

A DPA, including SCCs for international transfers, is available to customers. Request it at privacy@abscode.com.

Report a vulnerability

We welcome responsible disclosure. If you believe you have found a security issue, email security@abscode.com. Please do not publicly disclose until we have responded. For confirmed personal-data breaches, we notify affected customers and authorities as required by applicable law.

Read our Privacy Policy