Security

Security built for teams and companies

Your work belongs to your team and no one else. This is how we protect the projects, tasks, and files you trust Doku with.

The controls, one by one

What each layer protects, on which infrastructure, and with which concrete measures.

Encryption in transit

All traffic

Everything travelling between your browser (or the desktop app) and our servers is encrypted. There are no unencrypted routes.

Cloudflare
TLSHTTPS enforcedNo unencrypted routes

Identity and sessions

Authentication

Easy for your team to get in, hard for anyone else. Signing out invalidates access on the server, not just on the device.

OAuth with Google and GitHubDoku never sees those passwordsRevocable session tokensPasswords hashed (bcrypt)

Per-space isolation

Database

Every query verifies your space membership inside the same SQL statement. No membership, no data — not even through a coding mistake.

Google Cloud
Membership check on every queryPermissions resolved server-sideRoles: viewer, member, admin

Files and attachments

Storage

Files live outside the database, in object storage, and are only served to people who belong to the space.

Cloudflare
Separate from the databaseAuthenticated members onlyNon-guessable paths

Sharing with control

Public links

Sharing outward is an explicit decision, never an accident. Everything else requires signing in and being a member.

Cryptographically strong random tokensOptional password (bcrypt)Revocable and regenerable

Managed infrastructure

Operations

Less surface, less risk: we don't run our own servers to patch. The API runs at the edge and the database is a managed service.

CloudflareGoogle Cloud
No self-managed serversPatching handled by the providerAutomatic backups

AI with clear boundaries

Doku's assistant processes your data on Vertex AI (Google Cloud), whose enterprise terms state your data is not used to train foundation models. The assistant only reaches the spaces you have access to — the same membership rules apply to the AI.

Responsible disclosure

Found a vulnerability? We want to know. Write to us and we'll get back to you promptly — we publicly credit responsible reports.

Report to [email protected]

Does your company need more detail?

Tell us what your security or compliance team needs and we'll reply with specifics on architecture, data, and process.

Email [email protected]Create a free account