Security, without the marketing words.
Dockt holds passports, policies, medical letters and bills. That deserves a straight explanation rather than a row of badges. This page describes how the product actually works today.
What we encrypt
Everything you send to Dockt is encrypted in transit (TLS 1.2+) and encrypted at rest in our storage and database layers. Backups are encrypted with the same standard and access to production systems requires multi-factor authentication and is logged.
What we do not claim
Dockt is not end-to-end encrypted, and we will not say that it is. End-to-end encryption means the service itself cannot read your content. Dockt's entire purpose is to read your documents and emails so it can extract dates and warn you before a deadline — which requires our systems to be able to decrypt and process them. Those two things are mutually exclusive. Anyone promising both is describing something they haven't built.
What our systems read, and when
- Only content you send us: what you forward to your private address, share to the app, or upload.
- We do not connect to your mailbox and we do not scan your inbox.
- Processing is automated, for extraction and reminders only — never for advertising or profiling.
- Human access to your content happens only when you ask for support and grant it, or where we are legally compelled. Every such access is logged.
Who can see your things
You, and the specific people you share a specific thing with. Dockt does not have a shared household account that exposes everything to everyone in it. Access is granted per item, with a role (view, edit, or reminders only), and can be revoked at any time. Revoking a share removes access immediately.
Where your data lives, and for how long
- Hosted with established cloud infrastructure providers under data-processing agreements.
- Deleting an item removes it from the live product immediately and from backups within 35 days.
- Closing your account deletes your content on the same schedule. We keep only what law requires, such as billing records.
- You can export everything you have captured at any time, in a portable format, including after you stop paying.
We do not sell your data
Not to advertisers, not to data brokers, and not for training third-party models. Subscriptions are our only source of revenue, which is deliberate.
Certifications
Dockt is an early-access product and we hold no third-party security certification today. When that changes, this page will name the standard, the auditor and the date — and not before. We would rather be honestly uncertified than vaguely "enterprise grade".
If something goes wrong
If we discover a breach affecting your data, we will tell you directly and promptly — what happened, what was affected, and what we are doing — alongside any regulator notification we are required to make. We will not bury it in a status page.
Reporting a vulnerability
A vulnerability disclosure process will be published here once we have a formal security program in place. We will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service disruption.
Last reviewed: July 2026. This page describes current practice and is not an independent audit or certification.