Skip to main content
Security and Compliance

Security built for regulated industries

SOC 2 Type II. ISO 27001. AES-256 encryption at rest. Private AI. Granular permissions. Complete audit trails. Everything regulated teams need to say yes to a new platform without spending months in security review.

  • SOC 2 Type II and ISO 27001 Certified
  • Trusted since 1994
  • 4.2/5 on G2
RocketDocs | Project Details R PROJECT DETAILS Summary Open Requests Questions Attributes Audit Trail Notes DDQ Demo Project Summary REASSIGN REVERT PROMOTE MENU Review Manager (Group) Populate Finalize Project ID: 37 | Type: Security Questionnaire | Lead: Nancy Drew | Status: draft | Client: ABC Company Audit Trail DATE USER ACTION DETAILS 9 Feb 2026, 10:08 AM Drew, Nancy AutoParse Parsed questions from SaaS RFP 9 Feb 2026, 10:08 AM Drew, Nancy ProjectQuickAdd Create Project Quick Add 8 Feb 2026, 3:42 PM Manning, B. ContentEdit Updated encryption policy 8 Feb 2026, 2:15 PM Chen, L. StatusChange Promoted to Review 7 Feb 2026, 4:30 PM Park, J. Autofill Autofilled 247 of 299 (83%) Rows per page: 25 | 1-5 of 12

Eating our own dog food

We use RocketDocs to maintain our own security responses

When a customer or auditor asks for our SIG, our CAIQ, our SOC 2 supporting questionnaire, or our latest compliance attestations, we respond from RocketDocs. Same platform you use. Same audit trail. Same private AI. The result is that our own security responses are always current, always traceable, and always available through the Trust Center.

Not many vendors can say their security questionnaire process is run on the platform they sell. We can.

Certifications

The certifications regulated buyers expect

  • SOC 2 Type II: independent audit of security controls covering security, availability, processing integrity, confidentiality, and privacy
  • ISO 27001: international standard for information security management systems
  • Annual recertification with up-to-date audit reports available through the Trust Center

Encryption

AES-256 at rest. TLS 1.2+ in transit.

All customer data is encrypted at rest using AES-256. Data in transit is encrypted using TLS 1.2 or higher. Encryption keys are managed through industry-standard key management practices.

  • AES-256 encryption at rest
  • TLS 1.2 or higher in transit
  • Industry-standard key management
  • Independent third-party penetration testing

Private AI architecture

No third-party model provider in the data path

Astro, the platform's generative AI engine, runs on Llama 3.1 hosted inside the RocketDocs environment. Customer data is never sent to OpenAI, Anthropic, Google, or any other third-party model provider. For regulated industries, this is an AI architecture built to survive compliance review.

  • Llama 3.1 hosted privately inside the RocketDocs environment
  • No OpenAI, Anthropic, Google, or other model providers in the data path
  • Customer data never used to train any AI model
  • Every AI action logged in your audit trail

Permissions

Granular permissions at every level

Granular permissions are enforced at every level of the platform.

  • User-level permissions: each user has a defined role with specific access rights
  • Role-based access control: permissions assigned to roles, users assigned to roles
  • Group-level permissions: shared access for cross-functional teams
  • Content-level permissions: restrict access to sensitive content records, libraries, or topics
  • Project-level permissions: control who can view, edit, or approve specific projects
  • SSO and SCIM: identity managed through your existing identity provider
  • Multi-factor authentication: enforced through your identity provider

Audit trail

Every action logged. Every change versioned.

Every action in the platform is logged. Every change is versioned. Every approval is tracked. The audit trail is immutable and exportable.

  • User actions: login, content access, content edits, content approvals, project changes
  • Content history: complete version history per content record, with diff tracking
  • Project history: every workflow stage transition, every assignment, every approval
  • Export history: every document exported, with timestamp, user, and content fingerprint
  • Audit reporting: queryable audit reports for compliance review and customer audit response

Compliance frameworks

Designed to support each framework regulated industries answer to

  • Financial services: SOX, GLBA, FINRA, OCC vendor management expectations
  • Healthcare: HIPAA-aligned content handling and audit requirements
  • Life sciences: 21 CFR Part 11-aligned workflows including immutable audit trails, structured approvals, and full export history
  • Government and defense: NIST 800-171, CMMC alignment patterns supported
  • Cross-industry: GDPR, CCPA data handling expectations

Trust Center

Full documentation in the Trust Center

SOC 2 audit reports, ISO 27001 certificates, penetration testing summaries, and our complete security questionnaire responses are available through the RocketDocs Trust Center.

What customers say

Trusted by the teams whose responses cannot be wrong

4.2/5 on G2
The tool itself is very simple and direct. I've trained a lot of people on this and they're like, that's all I have to do? It's the way that RocketDocs works with Word. It's very similar to what they're used to. It's very user friendly.
RFP Manager , Leading Global Bank
RocketDocs has competitors in the space. But none of them can do what RapidDocs does. I haven't found any that are as good in product suite. So RapidDocs, from my perspective, is pretty unique. It's a great tool. It can save you time. It can help you to do things a lot easier.
Vice President , Leading Global Bank
Problems are the same for all RFP teams: finding the correct data at the right time, and organizing data into useful libraries and subtopics. RocketDocs allows us to manage more than 10 different lines of business and keep our data organized and structured.
G2 Reviewer
After over 20 years of using different RFP database management systems, I am impressed with the usability and ease of organization in the system. The speed with which my team can locate and update responses is impressive.
G2 Reviewer

FAQ

Frequently asked questions

Is RocketDocs SOC 2 Type II certified?

Yes. RocketDocs holds a current SOC 2 Type II certification. The audit report is available to customers and qualified prospects through the Trust Center.

Is RocketDocs ISO 27001 certified?

Yes. RocketDocs holds a current ISO 27001 certification. The certificate and supporting documentation are available through the Trust Center.

How is customer data isolated between tenants?

Customer data is logically isolated, with permissions enforced at the database, application, and API levels. No customer can access another customer's data through any path. Multi-tenant architecture details are documented in our security review materials, available under NDA.

Does RocketDocs use customer data to train AI models?

No. Customer data is not used to train Astro or any other AI model. Your knowledge base, your responses, and your customer information are never sent to third-party AI providers and never used to train public models.

What encryption standards does RocketDocs use?

AES-256 for data at rest. TLS 1.2 or higher for data in transit. Encryption keys are managed through industry-standard key management practices.

Can RocketDocs support our data residency requirements?

US and EU data residency are supported. For specific residency requirements, including country-specific or regulatory-specific constraints, talk to a specialist.

What is your incident response process?

RocketDocs maintains a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. Customers are notified of any incident affecting their data within the timeframes required by SOC 2 and applicable regulatory frameworks.

Free resource

Pressure-test your AI stack

Pressure-test any AI vendor in your stack. Eight questions on data privacy, security, governance, and compliance.

--
out of 100
Answer to begin
Question 1 of 8 · Data Privacy

Where does the vendor's AI model run?

Question 2 of 8 · Data Privacy

Is your data used to train the vendor's AI model?

Question 3 of 8 · AI Governance

Who owns and controls the AI model?

Question 4 of 8 · AI Governance

Can you trace AI outputs back to source content?

Question 5 of 8 · Compliance

Does the vendor hold SOC 2 Type II certification?

Question 6 of 8 · Compliance

Does the vendor hold ISO 27001 certification?

Question 7 of 8 · Audit & Governance

Are AI decisions fully auditable?

Question 8 of 8 · Security

How is data encrypted?

Ready to take a closer look?

A specialist will walk you through the platform's security architecture in the level of detail your security team requires. For deep technical review, we can pre-arrange a session with our CTO and security engineering team.