Skip to main content

Trust Center

Last updated: 7 September 2026

Northdocs ApS entity registration (CVR) is pending. These policies describe how the service operates today and are intended for customer due diligence. For a countersigned DPA or negotiated terms, contact legal@northdocs.com.

1. Overview

This Trust Center is the public diligence pack for InfoSec, privacy, and procurement. It covers EU hosting on OVHcloud Frankfurt, fail-closed redaction, optional AI (including Conversation Redact speech-to-text), Outbound Guard telemetry, Prompt Guard, identity (Clerk), self-serve payments (Stripe), and how to execute the DPA.

For Enterprise evaluations, invoice licensing, or SSO onboarding, contact sales@northdocs.com · legal@northdocs.com.

2. Diligence documents

Accessibility

Public sector / Procurement

WCAG 2.1 AA statement: conformance status, axe-core CI, scope (including Help and the app shell), known limitations, and a five-business-day feedback target.

Open

Security Overview

InfoSec

Fail-closed export, EU residency on OVHcloud Frankfurt, isolated PDF/OCR, envelope encryption, optional Azure Key Vault BYOK, AI kill-switch, backups and recovery, secure development, incident response, and vulnerability reporting.

Open

Architecture

InfoSec / IT

Trust boundaries, processing pipeline, residency, encryption (including BYOK), resilience and change control, Conversation Redact speech-to-text, and optional Outlook send-time protection.

Open

Enterprise AI Policy

Privacy / InfoSec

Optional OVHcloud AI Endpoints from the EU app for NER, Magic, summaries, Prompt Guard, Outbound Guard names, and Conversation Redact speech-to-text, plus the organization kill-switch.

Open

Security questionnaire

InfoSec / Procurement

SIG-lite Q&A for vendor assessments: hosting, SSO, AI, connectors, resilience, secure development, incident response, certifications roadmap, and contacts.

Open

Subprocessors

Privacy / Legal

Article 28 register: OVHcloud (hosting and optional AI), Scaleway TEM, Clerk, Stripe, and customer-configured connectors.

Open

Data Processing Addendum

Legal / Privacy

Downloadable and in-app e-accept Art. 28 DPA for customer documents, cases, and related processing.

Open

Privacy Policy

Privacy

Controller versus processor roles, documents, Outlook telemetry, conversation audio, Prompt Guard, retention, and rights.

Open

Cookie Policy

Privacy

Strictly necessary Clerk and locale cookies, no advertising cookies, and how to manage them.

Open

Terms of Sale & Service

Legal / Procurement

Commercial terms, human-review responsibility, warranties, and availability language.

Open

4. Scope and roadmap

Northdocs is EU-first SaaS with published controls. For procurement, here is the current status on common diligence items:

  • SOC 2 / ISO 27001: on the roadmap. Ask legal@northdocs.com for the latest status letter.
  • Production AI uses OVHcloud AI Endpoints in the EU (NER, Magic, summaries, Prompt Guard names, Outbound Guard names, and Conversation Redact speech-to-text). Organization admins can disable AI / ML detection under Settings so document content is not sent to an AI provider. Audio without captions then needs a WebVTT or SubRip sidecar. Questions: support@northdocs.com.
  • Uptime SLA: quantitative commitments are available on Enterprise by written agreement. A public status page is forthcoming. Incident notices for affected customers go through support and email.
  • Data residency: Germany / EU by default (OVHcloud Frankfurt, data region eu-de). US residency is not offered.
  • Identity: Enterprise SSO/SAML is available. SCIM (join/move/leave) is offered via Clerk Directory Sync on Enterprise connections; ask sales to enable for your tenant.
  • Payments: Stripe processes self-serve checkout and invoices. Northdocs does not store full card numbers. See Subprocessors.
  • Encryption at rest: OVH S3-compatible object storage (Germany) by default. Enterprise can enable per-document envelope encryption and optional Azure Key Vault BYOK (customer CMK wraps the organization key; Northdocs never stores the CMK). At-rest object storage only; not in-memory processing. See Security Overview, Architecture, and the Security questionnaire.
  • Outbound Guard telemetry stores mailbox, finding counts, destination class, and domains. It does not store message bodies or raw CPR.
  • Resilience: automated daily database backups to EU object storage in the same region, with restores rehearsed on isolated infrastructure. Northdocs runs in a single EU region by design, so there is no cross-region failover that would move documents outside the agreed region. RTO and RPO targets are available on Enterprise by written agreement.
  • Incident response: security and availability events are triaged on detection. For a personal data breach affecting customer personal data, Northdocs notifies affected customers without undue delay with the information needed for Article 33 and 34 obligations. The binding commitment is in the DPA; escalation goes to security@northdocs.com.
  • Change control: production changes go through peer-reviewed pull requests with type checking and an automated test suite, including pinned regression tests for tenant isolation, fail-closed export, and outbound URL filtering. Physical and datacenter certifications are inherited from OVHcloud.

5. Availability

Standard Terms do not include a public quantitative uptime commitment. Enterprise customers can agree a written SLA in the Order Form / MSA.

A public status page is forthcoming. Incident notices for affected customers go through support and email. The page will cover the app, OVHcloud AI Endpoints, Clerk, and the PDF/OCR container once it is live.

6. Contact

Security / vulnerability reports
security@northdocs.com

Acknowledge within 2 business days; status update within 10 business days.

Privacy
privacy@northdocs.com

Data protection questions and DPA coordination.

Legal / negotiated paper
legal@northdocs.com

MSA, countersigned DPA, status letters, Enterprise commercial terms.

Sales / Enterprise evaluation
sales@northdocs.com

Trials, bake-offs, invoice licensing, SSO onboarding.