Skip to main content
Doctorine
Menu

Trust Center

A starting point for security review: implemented controls, explicit boundaries, declared subprocessors, and vulnerability reporting.

Security posture

Data residency

EU data-at-rest by construction; US carve-outs are disclosed rows, never hidden (docs 04/19/34).

The full, CI-gated subprocessor and residency table is published at /trust/subprocessors/. Dependencies matching the manifest's vendor markers cannot pass the trust-surface gate without a disclosed row. Contract and infrastructure review cover data flows that a package marker cannot detect.

Compliance

Doctorine is not currently claiming SOC 2 certification. The control scaffold exists; an audit report remains post-GA work. We act as processor for customer workspace content under the applicable DPA, with transfer bases disclosed for non-EU subprocessors. Incident tooling defines a 48-hour customer-notification target, but the automated breach clock and delivery receipt remain rollout work; executed customer terms govern.

Report a vulnerability

We operate a responsible-disclosure policy with safe harbor: /trust/security/, machine-readable at /.well-known/security.txt (RFC 9116). Email security@doctorine.xyz.