Botdoc
What is SDT SDT Engine Built on SDT Partners About Blog Spark Login Talk to the team

Security and Compliance at Botdoc

Botdoc moves regulated documents for banks, healthcare systems, schools, and dealerships. Our security posture is examined annually and documented for customer review.

Quick links:

  • Independent Examination
  • Encryption
  • Infrastructure
  • Regulatory Alignment
  • Access and Authentication
  • Monitoring and Testing
  • Verify Us
  • Report Issues

Independent Examination

Botdoc's controls are examined annually under SOC 2 Type 2 (Security Trust Services Criteria). Our most recent report covers the full 2025 calendar year with a clean, unqualified opinion. The report and our 161-control vendor risk assessment, mapped to the NIST Cybersecurity Framework, are available to customers and partners under NDA.

Encryption

Documents are encrypted in transit with TLS and at rest with AES-256, under per-transaction keys generated and stored in Azure's hardened key store, where no person can view them. There is no master key. Data is purged automatically after the delivery window.

Infrastructure

Botdoc runs on Microsoft Azure, which maintains its own ISO/IEC 27001 certification and independent attestations. Botdoc's application-layer controls are examined separately under our SOC 2 program.

Regulatory Alignment

  • GLBA / FTC Safeguards Rule. Encryption of customer information in transit, access controls, monitoring, and service-provider oversight.
  • HIPAA. Safeguards for ePHI in transit with audit controls and minimum-necessary access.
  • PCI DSS. Compliant as service provider and merchant.
  • GDPR and FERPA. Control framework designed for compliance; documentation available on request.
  • EU-U.S. Data Privacy Framework. Botdoc aligns its cross-border data handling with the EU-U.S. Data Privacy Framework principles.

Access and Authentication

Multi-factor authentication is enforced on production systems and employee accounts. Single sign-on is supported via Auth0, with Okta integration available. Access follows least privilege with logged administrative activity.

Monitoring and Testing

Continuous 24x7 monitoring with independent weekly vulnerability scanning. We maintain a public vulnerability disclosure policy and welcome good-faith security research: botdoc.io/our-terms/vulnerability-disclosure/. Botdoc is a CISA Secure by Design pledge signatory.

Verify Us

Request the compliance portfolio (SOC 2 Type 2 report, vendor risk assessment, policies, insurance certificate) through your account contact or sales@botdoc.io. Right to audit is granted to clients and their member associations.

Report Issues

System failures, suspected incidents, or general issues: support@botdoc.io. Suspicious or fake emails: forward the entire email, including header information, to support@botdoc.io, then delete it from your mailbox. Unethical behavior: anonymous@botdoc.io.

Updates and Alerts

Routine maintenance, new features, fixes, updates and other important announcements appear on the Botdoc blog.

View the latest updates and announcements on the Botdoc blog →

Botdoc

Inventor and steward of Secure Digital Transport.

Product

What is SDT SDT Engine Built on SDT Custom Developer? API console →

Company

About Press Security Support Blog

Legal

Privacy Terms Security center Vulnerability disclosure Patents Google API
© 2026 Botdoc. All rights reserved. 1909 Woodmoor Dr, Monument CO 80132 · 719-960-4767

We value your privacy

We use cookies to improve your experience and analyze site traffic. By continuing to browse, you accept our use of cookies. See our Privacy Policy.

Schedule a call