Security at Docket
last updated 11 Aug 2026Draft pending production-control verification. This page describes the security contract Docket is preparing for launch and must not be treated as proof of deployment or certification.
Minimum necessary data
Docket limits protected customer fields to name, billing and shipping addresses, and email for document generation, retrieval, export, support reconciliation, and deletion. It does not request or retain customer phone values or order notes.
Access and credentials
Production access is limited to an authorized-operator role using individual provider identities, least privilege, provider-enforced MFA, and separately scoped credentials. Protected operations are authenticated and produce a pseudonymous audit intent before access.
Encryption and environments
Public and provider traffic uses encrypted transport. Cloudflare provides encryption at rest for managed storage. Development and staging use isolated synthetic data and separate credentials; production data is not copied into them.
AI boundary
Protected customer data never enters a language-model prompt or tool result. Support models receive deliberately submitted text, non-protected product knowledge, and limited safe operational references. Authenticated and pre-sales model caching is disabled, and data is not used for model training, profiling, advertising, or significant automated decisions.
Retention, deletion, and recovery
One canonical retention registry controls timed expiry. Customer redaction removes the matching customer's records; uninstall and shop redaction purge shop state and invalidate old links. Docket creates no application-managed backup. Provider-managed encrypted durability and recovery copies cannot return to service until required deletion records are replayed and absence is verified.
Report a security concern
Send an initial report to security@docketpdf.com. Include a concise description and safe reproduction steps, but do not include customer data, documents, credentials, or access links. Docket triages reports under its incident-response policy and reports an actual or suspected merchant-data breach to Shopify immediately and no later than 24 hours after awareness.