Security
Security at Doqubox
The technical and organizational safeguards behind secure document requests, uploads, and delivery.
Last updated: 6 October 2026
1. Security approach
Doqubox protects document exchange with secure links, recipient verification, encryption, passkeys, retention controls, and EU hosting.
Doqubox itself is not certified under ISO 27001, SOC 2, NEN 7510, or NTA 7516.
2. Architecture
Documents are exchanged through upload, download, and request links. External recipients can be verified with one-time codes.
3. Encryption and access
Files and their metadata, including original filenames and file types, are end-to-end encrypted in the sender's browser and decrypted in the recipient's browser.
Account, verification, billing, log, and email or SMS delivery data are outside this end-to-end encryption. Traffic is encrypted in transit, stored files and metadata remain encrypted, and service data has access controls.
4. Account security
- Approved account users and administrators authenticate with passkeys.
- Activity records show uploads, access, downloads, and deletions.
5. Retention and minimization
Temporary messages and files expire according to retention settings. Billing, security, and statutory records may be kept longer. See the retention policy.
6. Infrastructure and subprocessors
Application hosting, databases, object storage, backups, and outbound email infrastructure are in the EU. Provider details and processing locations are in the subprocessor list.
7. Operational safeguards
- Production access is limited to people with an operational need.
- Security events and logs support troubleshooting and incident response.
- Backups and recovery procedures support continuity.
- Dependencies and infrastructure are reviewed during maintenance.
8. Important limitations
Doqubox cannot inspect encrypted file content, including for malware. Customers need suitable endpoint protection and internal checks and remain responsible for document selection and recipients.
9. Responsible disclosure
Report vulnerabilities to security@doqubox.com with reproduction steps, the affected feature, and potential impact. Include evidence where safe, avoiding personal data unless strictly necessary.
- Do not destroy, modify, download, or disclose others' data. Stop and report if you encounter customer data or another account.
- No social engineering, phishing, spam, denial-of-service testing, or physical attacks.
- Allow reasonable time to investigate and fix issues before disclosure.
We aim to acknowledge reports within 3 business days. We do not offer a paid bug bounty.
10. Related resources
Independently reviewed by EU VETTEDFor other security questions, contact support@doqubox.com.