Security and Compliance
Security built for regulated industries
SOC 2 Type II. ISO 27001. AES-256 encryption at rest. Private AI. Granular permissions. Complete audit trails. Everything regulated teams need to say yes to a new platform without spending months in security review.
- SOC 2 Type II and ISO 27001 Certified
- Trusted since 1994
- 4.2/5 on G2
Eating our own dog food
We use RocketDocs to maintain our own security responses
When a customer or auditor asks for our SIG, our CAIQ, our SOC 2 supporting questionnaire, or our latest compliance attestations, we respond from RocketDocs. Same platform you use. Same audit trail. Same private AI. The result is that our own security responses are always current, always traceable, and always available through the Trust Center.
Not many vendors can say their security questionnaire process is run on the platform they sell. We can.
Put us through the same scrutiny. These five governance tests are the ones worth running during a pilot, because they ask a platform to prove a claim was approved rather than describe how approvals work.
Certifications
The certifications regulated buyers expect
- SOC 2 Type II: independent audit of security controls covering security, availability, processing integrity, confidentiality, and privacy
- ISO 27001: international standard for information security management systems
- Annual recertification with up-to-date audit reports available through the Trust Center
Encryption
AES-256 at rest. TLS 1.2+ in transit.
All customer data is encrypted at rest using AES-256. Data in transit is encrypted using TLS 1.2 or higher. Encryption keys are managed through industry-standard key management practices.
- AES-256 encryption at rest
- TLS 1.2 or higher in transit
- Industry-standard key management
- Independent third-party penetration testing
Private AI architecture
No third-party model provider in the data path
RocketDocs runs its own private AI, with a dedicated document store for each customer. Your data is never sent to public AI providers and never used to train any model. For regulated industries, this is an AI architecture built to survive compliance review.
- Private AI, RocketDocs-run, with a dedicated document store for each customer
- No OpenAI, Anthropic, Google, or other model providers in the data path
- Customer data never used to train any AI model
- Every AI action logged in your audit trail
Permissions
Granular permissions at every level
Granular permissions are enforced at every level of the platform.
- User-level permissions: each user has a defined role with specific access rights
- Role-based access control: permissions assigned to roles, users assigned to roles
- Group-level permissions: shared access for cross-functional teams
- Content-level permissions: restrict access to sensitive content records, libraries, or topics
- Project-level permissions: control who can view, edit, or approve specific projects
- SSO and SCIM: identity managed through your existing identity provider
- Multi-factor authentication: enforced through your identity provider
Audit trail
Every action logged. Every change versioned.
Every action in the platform is logged. Every change is versioned. Every approval is tracked. The audit trail is immutable and exportable.
- User actions: login, content access, content edits, content approvals, project changes
- Content history: complete version history per content record, with diff tracking
- Project history: every workflow stage transition, every assignment, every approval
- Export history: every document exported, with timestamp, user, and content fingerprint
- Audit reporting: queryable audit reports for compliance review and customer audit response
Compliance frameworks
Designed to support each framework regulated industries answer to
- Financial services: SOX, GLBA, FINRA, OCC vendor management expectations
- Healthcare: HIPAA-aligned content handling and audit requirements
- Life sciences: 21 CFR Part 11-aligned workflows including immutable audit trails, structured approvals, and full export history
- Government and defense: NIST 800-171, CMMC alignment patterns supported
- Cross-industry: GDPR, CCPA data handling expectations
Trust Center
Full documentation in the Trust Center
SOC 2 audit reports, ISO 27001 certificates, penetration testing summaries, and our complete security questionnaire responses are available through the RocketDocs Trust Center.
What customers say
Trusted by the teams whose responses cannot be wrong
Our project load has consistently increased year over year for many years. I tie our ability to keep meeting that, without hiring more people, to RocketDocs.
Things that could have taken a half an hour can now take possibly a minute. It is absolutely a massive time saver in keeping hundreds and hundreds of answers ready to go for us to use.
Not only are sales representatives creating better proposals, but they’re also doing it in a fraction of the time it used to take, which frees them up to spend more time in front of customers or to pursue more sales opportunities.
FAQ
Frequently asked questions
Is RocketDocs SOC 2 Type II certified?
Yes. RocketDocs holds a current SOC 2 Type II certification. The audit report is available to customers and qualified prospects through the Trust Center.
Is RocketDocs ISO 27001 certified?
Yes. RocketDocs holds a current ISO 27001 certification. The certificate and supporting documentation are available through the Trust Center.
How is customer data isolated between tenants?
Customer data is logically isolated, with permissions enforced at the database, application, and API levels. No customer can access another customer's data through any path. Multi-tenant architecture details are documented in our security review materials, available under NDA.
Does RocketDocs use customer data to train AI models?
No. Customer data is not used to train Astro or any other AI model. Your knowledge base, your responses, and your customer information are never sent to third-party AI providers and never used to train public models.
What encryption standards does RocketDocs use?
AES-256 for data at rest. TLS 1.2 or higher for data in transit. Encryption keys are managed through industry-standard key management practices.
Can RocketDocs support our data residency requirements?
US and EU data residency are supported. For specific residency requirements, including country-specific or regulatory-specific constraints, talk to a specialist.
What is your incident response process?
RocketDocs maintains a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. Customers are notified of any incident affecting their data within the timeframes required by SOC 2 and applicable regulatory frameworks.
Free resource
Pressure-test your AI stack
Pressure-test any AI vendor in your stack. Eight questions on data privacy, security, governance, and compliance.
Ready to take a closer look?
A specialist will walk you through the platform's security architecture in the level of detail your security team requires. For deep technical review, we can pre-arrange a session with our CTO and security engineering team.