Security
Security.
docket is built for people who look after other people's buildings. That only works if you can trust us with the data, so here is exactly how it's handled, in plain terms.
Tenant isolation, enforced by the database.
Every docket customer is a separate tenant, and isolation is enforced at the database layer using row-level security, not just in application code. The application connects through a restricted database role that cannot bypass these rules, and the platform checks this on every startup: if isolation were ever misconfigured, docket refuses to run rather than running unsafely. The same check is exposed on a live health endpoint, continuously.
Where your data lives.
docket runs on cloud infrastructure in the EU. Data is encrypted in transit (HTTPS/TLS) and at rest.
Access and accounts.
Passwords are never stored, only industry-standard salted hashes (bcrypt). Login endpoints are rate-limited against automated guessing. Password resets use single-use, expiring tokens; no password is ever sent by email. Sessions use secure, HTTP-only cookies.
People and process.
docket is operated from the UK and handles data in line with UK GDPR. Client data is never sold or shared, and is used only to run the service.
How the AI handles your documents.
When docket reads an email, a job sheet or a certificate, the document is sent over an encrypted connection to our AI provider, which returns the structured result. It is not kept by the provider beyond a short operational window, and it is never used to train AI models. The only permanent copy is the record in your docket account, held in the EU. Everything the AI produces is a draft. A person in your business reviews and approves it before it becomes a job, a record or anything else. Nothing is created or closed automatically.
Questions, or a security requirement we should know about? hello@docketfm.co.uk
See your inbox
empty itself.
Tell us what your Monday morning looks like and we'll show you what docket takes off you.