Isolated by design
Production and sandbox instances belong to one tenant and keep their application data separate from every other tenant.
SECURITY AND DEPLOYMENT
Every tenant runs in an isolated application and data environment. Choose our managed service in the Netherlands, or run Docusense inside your own infrastructure. This page covers the boundary and the two options. A companion page goes through the same ground at component level for an IT review.
TENANT ISOLATION
Application services, the database, vector store, file storage, internal network, and runtime secrets are separated for each tenant. Knowledge and questionnaire data do not cross that boundary.
Production and sandbox instances belong to one tenant and keep their application data separate from every other tenant.
Permission profiles and customer assignments control which questionnaires and records a user can access inside the tenant. The two layers are independent and both apply.
Use passwords, passkeys, MFA, Microsoft Entra ID, or another OpenID Connect provider to suit your environment.
Three terms are used precisely in the product. A tenant is the subscribing organization and the isolation boundary. A customer is a business record inside that tenant. An instance is one production or sandbox environment belonging to a tenant. Optional cross-customer matching means matching between customer records inside your own tenant, it can be disabled, and it never means matching across tenants.
DEPLOYMENT
The managed and self-hosted options use the same review workflow. The difference is where the application and its supporting services operate.
We operate an isolated environment for your tenant. You receive one production instance and two sandboxes, so releases can be reviewed before production is upgraded.
Managed tenants are isolated with separate container stacks on shared infrastructure. Managed AI model infrastructure is shared, and prompts and documents sent to it are processed without being retained or used for model training.
Self-hosted Docusense keeps the application, document processing, and AI model services in your environment. The core deployment can operate without an internet connection.
You control the infrastructure, identity, recovery, updates, and model capacity, and you are not committed to one vendor's models. Any endpoint that speaks the expected interface can be configured, including models you host on your own hardware.
If your requirement is that no document content is processed on infrastructure shared with anyone else, the self-hosted option is the one that meets it. We would rather say that plainly than argue the point during a security review.
MANAGED SERVICE
Our managed service starts with daily immutable backups. We agree the encryption, backup, and release setup with you before the environment goes live.
A full snapshot is stored off-site in the same region each day. Frequency and retention can be changed for your tenant.
Database and storage protection can be configured at several layers to meet the requirements agreed with your team. There is no single fixed design applied to every tenant.
We do not push releases automatically. Preview a release in a sandbox against your own data before scheduling the production upgrade.
TECHNICAL REVIEW
We can go through the tenant boundary, authentication, data flow, model services, backups, and the upgrade process against the controls your organization needs, with the people who built it.
Incident response detail, support hours, response targets, availability, and SLA terms are specific to each customer agreement rather than published as a standard promise. Thepage for IT and security teamslists the questions we would expect to be asked.