Security

Trusted knowledge needs clear boundaries.

An overview of Docpipe’s current data protection, authentication, authorization, and responsible AI controls.

Last updated · July 13, 2026
Knowledge controlsWorkspace policy
AI-proposed editsHuman review
Engineering spaceRestricted
Answer sourcesRequired
Unanswered questionsRoute to expert
ARNKJL3 subject-matter experts
01

Why it matters

Docpipe protects internal documentation, source context, and connected workflows with layered controls across data storage, authentication, authorization, and AI-assisted actions.

Built around the outcome—not the AI.

Each capability is useful on its own. Together, they make documentation easier to create, trust, and reuse.

01

Encryption

Connections use TLS. Managed database storage is encrypted at rest, with additional column-level protection for stored Slack bot tokens.

02

Tenant isolation

Supabase row-level security and server-side checks scope data access by organization, membership, privilege, and space visibility.

03

Scoped integrations

Slack, GitHub, and Confluence access is limited by installation choices, granted permissions, and configured workflows.

04

Human oversight

Citations, approval flows, feature flags, and granular edit review keep important AI output inspectable.

02

How it works

A clear path from work to trusted knowledge.

No content graveyard. No magic black box. Each step has an understandable output and owner.

01

Authenticate

Users sign in through supported identity flows and organization membership.

02

Authorize

Roles, privileges, document status, and space access determine available content and actions.

03

Audit the answer

Source citations and proposed-change review help teams verify AI output.

Product proof
TLSEncryption at restRow-level securityPer-space accessCited AI output
03

Common questions

What teams ask before they start.

Is Docpipe SOC 2 Type II certified?+

Contact security@docpipe.co for the latest audit status and the security documentation available for your review.

Does Docpipe use customer data to train language models?+

Docpipe does not use Slack data to train language models. Contact Docpipe for contract-specific AI data-processing details.

How do I report a vulnerability?+

Email security@docpipe.co with reproduction steps and allow a reasonable disclosure window.

Make the knowledge reusable

Need a deeper security review?

Ask for current security documentation, subprocessors, or data-processing details.

Contact security