Enterprise-grade security and trust

Docyt protects your financial data, at every layer.

See how Docyt protects your data and keeps it safe.

Docyt security: encrypted data, strong authentication and access controls

How Docyt keeps your data safe

SOC 2 Type II

Independently audited controls over security, availability and confidentiality, renewed annually.

Encryption

AES-256 encryption at rest, TLS in transit, encrypted backups, key management in the cloud provider's HSM-backed services.

Bank connectivity

Secure connections through Plaid and equivalent providers. Docyt never sees your banking credentials.

Access control

Single sign-on, two-factor authentication, role-based permissions, entity-level and department-level scoping, segregation of duties.

Biometric sign-in

Face ID and fingerprint unlock are supported wherever your device allows it, adding a hardware-bound step beyond your PIN.

Device-bound encryption

Your account and data are locked to your authenticated devices. Data in the cloud can only be decrypted using keys tied to your device, PIN and biometrics combined.

OAuth 2.0

Every connection to a partner or cloud service uses OAuth 2.0, the same authorization protocol standard used across banking and enterprise software.

Audit logs

Every read and write logged. Corrections are new entries; nothing is deleted. Every AI decision carries its explanation and reviewer.

AI data use

Your data runs your books. It is never used to train models for other companies and never sent to public models for training.

View-only access and roles

Grant owners, investors or auditors read-only visibility without edit rights. Every permission is scoped by role, entity and department, so people see exactly what they need and nothing more.

Data portability

Scheduled exports in open formats, API access for enterprise customers, documented data-return and wind-down process.

Document vault

Invoices, receipts and statements retained for seven years in an encrypted vault tied to ledger entries.

Availability

Redundant cloud infrastructure, continuous backups, published service status.

Data privacy

Customer data is segregated, encrypted and never used to train models for other companies. See exactly what we collect, how it's used and how long it's retained.

Read Our Privacy Notice→
AICPA SOC 2 Type II badge

FAQ

Frequently asked questions

Is Docyt SOC 2 compliant?

Yes. Docyt is SOC 2 Type II compliant, with controls over security, availability and confidentiality audited independently. The report is available to customers and prospects under NDA.

How does Docyt connect to my bank?

Through Plaid and equivalent secure bank connections. Docyt never sees or stores your online banking credentials.

Is my data used to train AI models for other companies?

No. Your documents and transactions are used to run your books and improve your own results. Customer data is segregated and encrypted, and Docyt does not send it to public models for training.

Who can see my data inside Docyt?

Only users you authorize, with role-based and entity-level permissions, and Docyt staff bound by access controls and audit logging for support and review.

Can I export my data?

Yes. Scheduled exports in open formats and a documented data-return process are part of every enterprise agreement. There are no exit penalties.

What happens if Docyt has an outage?

Docyt publishes service status at docyt.statuspage.io and maintains redundancy and backups across its cloud infrastructure.

See Docyt live

See how Docyt Enterprise Suite automates payments, accounting, and business intelligence, on one ledger.

  • Control spend
  • Stop revenue leakage
  • Zero-day close
  • Forecast with confidence

Get a personalized demo

We reply within one business day. No spam, no resale of your data. Privacy Policy.

Schedule a DemoPricing