/// TRUST CENTER

Where does ASHDOCS actually run, and who touches your data?

Every fact on this page is drawn directly from how ASHDOCS is built and deployed today — not aspirational, not marketing copy. See /security for encryption and threat-model detail, and /dpa for the legal terms.

Where does ASHDOCS run?

The API runs on a DigitalOcean droplet in the NYC1 region. The primary database is MongoDB Atlas in AWS us-east-1. Object storage (source files and outputs) is Cloudflare R2. The marketing site and customer dashboard are hosted on Vercel. All customer-facing traffic and processing happens in US-region infrastructure.

Is data encrypted?

In transit: TLS 1.2 or higher, everywhere. At rest: Cloudflare R2 encrypts stored objects server-side by default; MongoDB Atlas provides encryption at rest on the cluster tier ASHDOCS runs. Full technical detail, including how third-party credentials are encrypted before they reach the database, is on the security page.

How long is my data kept?

24 hours by default, then an automated sweep purges source files and outputs. Set options.retention="zero" per request, or the account-wide equivalent in the dashboard, and files are purged within minutes of the job finishing instead. This is the same retention behavior documented on the security page and in the DPA — one set of real numbers, not a different claim per page.

Who are ASHDOCS's sub-processors?

Sub-processorRole
DigitalOceanAPI compute hosting
MongoDB AtlasPrimary database
Cloudflare (R2)Object storage for source/output files
VercelMarketing site and dashboard hosting
ResendTransactional email
RazorpayBilling
AnthropicAI-driven structured data extraction — only invoked when you call pdf-to-data or a related tool

The full list, including two sub-processors that only activate for optional features (Google OAuth, PostHog analytics), is in the DPA.

What compliance certifications does ASHDOCS have?

None yet. ASHDOCS does not hold SOC 2, ISO 27001, HIPAA, or PDF/UA certification as of today, and this page won't claim one we haven't earned. What's real instead: the concrete technical controls on the security page, sandbox API keys that run every tool without touching production data, signed webhook deliveries, and a downloadable DPA template for your legal team to review.

Can I test without risking real data?

Every account gets a sandbox key (prefix ash_test_) that runs the full API — all 51 tools — without ever consuming credits or, for most tools, needing production data at all. Use it to validate integration and data handling before a single real document goes through.

Is ASHDOCS's own uptime public?

Yes — /status shows live 24h/7d/30d uptime and render latency, sourced from an independent synthetic health check, not just aggregated customer traffic.

Who do I contact about security or data handling?

Email security@ashdocs.com — the same address for a vulnerability report, a data-processing question, or a request for the countersigned DPA.