Docket
Features
  • Invoices
  • Packing slips
  • Credit notes
  • Quotes
Compare
  • vs Shopify Order Printer
  • vs Order Printer Pro
  • vs Sufio
  • vs Vify
  • Switch from Shopify Order Printer
  • Switch from Order Printer Pro
Resources
  • Docs
  • Changelog
Pricing Support
Install from Shopify
Docket
  • Features
    • Invoices
    • Packing slips
    • Credit notes
    • Quotes
  • Compare
    • vs Shopify Order Printer
    • vs Order Printer Pro
    • vs Sufio
    • vs Vify
    • Switch from Shopify Order Printer
    • Switch from Order Printer Pro
  • Resources
    • Docs
    • Changelog
  • Pricing
  • Support
Install from Shopify

Security at Docket

last updated 11 Aug 2026

Draft pending production-control verification. This page describes the security contract Docket is preparing for launch and must not be treated as proof of deployment or certification.

Minimum necessary data

Docket limits protected customer fields to name, billing and shipping addresses, and email for document generation, retrieval, export, support reconciliation, and deletion. It does not request or retain customer phone values or order notes.

Access and credentials

Production access is limited to an authorized-operator role using individual provider identities, least privilege, provider-enforced MFA, and separately scoped credentials. Protected operations are authenticated and produce a pseudonymous audit intent before access.

Encryption and environments

Public and provider traffic uses encrypted transport. Cloudflare provides encryption at rest for managed storage. Development and staging use isolated synthetic data and separate credentials; production data is not copied into them.

AI boundary

Protected customer data never enters a language-model prompt or tool result. Support models receive deliberately submitted text, non-protected product knowledge, and limited safe operational references. Authenticated and pre-sales model caching is disabled, and data is not used for model training, profiling, advertising, or significant automated decisions.

Retention, deletion, and recovery

One canonical retention registry controls timed expiry. Customer redaction removes the matching customer's records; uninstall and shop redaction purge shop state and invalidate old links. Docket creates no application-managed backup. Provider-managed encrypted durability and recovery copies cannot return to service until required deletion records are replayed and absence is verified.

Report a security concern

Send an initial report to security@docketpdf.com. Include a concise description and safe reproduction steps, but do not include customer data, documents, credentials, or access links. Docket triages reports under its incident-response policy and reports an actual or suspected merchant-data breach to Shopify immediately and no later than 24 hours after awareness.

Docket

Every document a Shopify order needs. Generated and stored.

Documents
InvoicesPacking slipsCredit notesQuotes
Compare
vs Shopify Order Printervs Order Printer Provs Sufiovs VifySwitch from Shopify Order PrinterSwitch from Order Printer Pro
Resources
DocsChangelogSupport
Company
PricingPrivacyTermsDPASecurity
© 2026 Docket · docketpdf.com one Unlimited subscription, never metered by order count