Skip to content
VAPT-Audited · Azure-Certified

Security Built Into Every Layer of DocullyVDR

Platform-level security you can audit, infrastructure-level certification you can verify, and a no-AI pledge you can hold us to.

Platform-Level Security

VAPT-audited against OWASP

DocullyVDR is VAPT (Vulnerability Assessment and Penetration Testing) audited against the OWASP framework — the industry-standard checklist for web-application security. That means the platform itself, not just the servers underneath it, has been independently tested against real-world attack patterns.

What VAPT Means

An independent security team attempts to breach the platform using the same techniques real attackers use — then reports every finding for remediation. OWASP is the framework they test against.

Vulnerability Assessment Penetration Testing OWASP Top 10 Independent Audit

Infrastructure-Level Security

Azure's global certifications, inherited

DocullyVDR is built on Microsoft Azure, so its infrastructure inherits Azure's own global security certifications — you get enterprise cloud security without having to become an Azure security expert yourself.

ISO 27001 SOC 1 SOC 2 SOC 3 HITRUST MeitY Accreditation CIS Benchmark CSA STAR Gold

99% Uptime with Daily Backup

Your data room stays available when your deal needs it, with daily data backups for recovery.

WAF & SSL Connectivity

Web Application Firewall and SSL connectivity protect against network-level attacks.

Two-Tier Authentication + Optional 2FA

Enterprise-class secure password protocol with optional two-factor authentication at sign-in.

Encryption & Access Control

Control down to the file level

256-bit AES Encryption

FIPS 140-2 compliant, for data in transit and at rest.

Granular Permissions

Folder, sub-folder, and file-level permissions.

Dynamic Watermarking

Timestamp, credentials, IP, and text on every document view.

Redaction

Redact sensitive content so it never leaves the room.

Auto-Revoke on Expiry

Access automatically revoked when a user's window expires.

Time-Bound Upload Windows

Restricted and time-bound upload windows for procurement.

Full Activity Logs

File and user-level activity logs for complete audit trails.

NDA-Gated Access

No agreement, no access

Before any participant can view a single document, DocullyVDR can require them to accept a custom NDA or click-through agreement — enforced at the platform level, not left to trust. This sits alongside the existing access control toolkit: granular folder and file-level permissions, dynamic watermarking, auto-revoke on expiry, and full activity logs. Together, they mean a participant cannot see, download, or print anything until they have formally accepted your terms — and every action they take afterward is tracked.

Custom NDA or click-through Enforced before file access Paired with watermarking & auto-revoke

How It Works

When a participant is invited to the room, they are presented with your NDA or click-through agreement before any document is visible. Only once they accept does access open — and from that point, every view, download, and print attempt is logged with their credentials, timestamp, and IP address.

  • Agreement required before first file view
  • Custom agreement text — your legal terms, not a template
  • Acceptance logged in the audit trail

How DocullyVDR Handles It

How DocullyVDR handles security

1

Platform-level VAPT audit

The platform itself — not just the infrastructure — is independently penetration-tested against the OWASP framework, covering real-world attack patterns.

2

Infrastructure certifications

Azure's own ISO 27001, SOC 1/2/3, HITRUST, MeitY, CIS Benchmark, and CSA STAR Gold certifications are inherited automatically.

3

Encryption at every layer

256-bit AES encryption, FIPS 140-2 compliant, for data in transit and at rest — plus a Web Application Firewall and SSL connectivity.

4

Access control enforcement

Folder, sub-folder, and file-level permissions, dynamic watermarking, and auto-revoke on expiry — so access is controlled and revocable.

5

Audit trail

Full activity logs at the file and user level, exportable for compliance review — every action tracked and timestamped.

Features That Matter Here

Security features in detail

256-bit AES Encryption

FIPS 140-2 compliant, for data in transit and at rest.

Dynamic Watermarking

Timestamp, viewer credentials, and IP stamped on every page viewed — deterring leaks.

Secure File Viewer

View-only mode with print and download blocking — documents never leave the room.

Redaction

Sensitive content removed before it's ever visible — permanently, not toggleable.

Auto-Revoke on Expiry

Access shuts off automatically when a user's window ends — no lingering access.

Full Activity Logs

Every file and user action tracked and timestamped — exportable for compliance review.

FAQ

Security questions

What does VAPT-audited against OWASP actually mean?

An independent security team attempts to breach the platform using the same techniques real attackers use, then reports every finding for remediation. OWASP is the framework they test against.

Can I get a copy of the audit documentation?

Yes — audit documentation is available on request. Contact us through the form below.

How does the no-AI pledge work in practice?

No AI model, LLM, or third-party plugin ever touches the documents inside your data room. It's not a feature toggle — it's a platform-wide architectural decision.

What Azure certifications does DocullyVDR inherit?

ISO 27001, SOC 1/2/3, HITRUST, MeitY accreditation (India), CIS Benchmark, and CSA STAR Certification at Gold level.

Our No-AI Pledge

No AI model, no LLM, and no third-party plugin ever touches the documents inside your data room. That's not a feature toggle — it's a platform-wide pledge, shared across the whole Docully product family.

No AI training No LLM processing No third-party plugins

Compliance Mapping

Host where your regulator expects

Choose a hosting region that matches your compliance obligations — GDPR-aligned hosting in the EU/UK, DPDP Act–aligned hosting in India, and region-appropriate hosting across the GCC, Singapore, the US, and Canada.

See the full list on our Data Hosting Locations page

GDPR

EU/UK Azure data centers, GDPR-aligned hosting.

DPDP Act

India data centers, DPDP-aligned hosting.

GCC & Singapore

Region-appropriate hosting across the Gulf and APAC.

US & Canada

North American Azure regions for US and Canadian deals.

Have a security questionnaire to complete?

Request our compliance pack — certification evidence, audit summaries, and infrastructure documentation ready for your security review.

Contact Us