DoControl · Trust Center

Docontrol Trust Center

Trust center

Certifications read from DoControl's own documentation page, which names them in plain text. This file was briefly overwritten on 2026-09-06 by an automated keyword probe that could only see HIPAA and GDPR — the marketing /security page is a JS-rendered Webflow page whose certification copy is not in the served HTML, so the probe found less than DoControl actually publishes. The documentation page is the stronger source and is used here.

DoControl maintains a public trust center documenting ISO 27001, SOC 2 Type II, HIPAA, and GDPR compliance.

Data SecuritySaaS SecurityData Access GovernanceData Loss PreventionInsider Risk ManagementSSPMGraphQLMCP
Trust center: https://www.docontrol.io/security

Certifications & Compliance

ISO 27001SOC 2 Type IIHIPAAGDPR

Source

Trust Center

Raw ↑
generated: '2026-09-06'
method: searched
probe: true
source: https://docs.docontrol.io/docontrol-user-guide/getting-started/overview/security-privacy-and-compliance.md
url: https://www.docontrol.io/security
description: >-
  Certifications read from DoControl's own documentation page, which names them in plain text.
  This file was briefly overwritten on 2026-09-06 by an automated keyword probe that could only
  see HIPAA and GDPR — the marketing /security page is a JS-rendered Webflow page whose
  certification copy is not in the served HTML, so the probe found less than DoControl actually
  publishes. The documentation page is the stronger source and is used here.
certifications:
- id: iso-27001
  name: ISO 27001
  evidence: 'Documentation states: "Compliance certifications (ISO 27001, SOC2 type II)"'
  source: https://docs.docontrol.io/docontrol-user-guide/getting-started/overview/security-privacy-and-compliance.md
- id: soc2-type-ii
  name: SOC 2 Type II
  evidence: 'Documentation states: "Compliance certifications (ISO 27001, SOC2 type II)"'
  source: https://docs.docontrol.io/docontrol-user-guide/getting-started/overview/security-privacy-and-compliance.md
- id: hipaa
  name: HIPAA
  evidence: HIPAA compliance claimed on the DoControl website.
  source: https://www.docontrol.io/
- id: gdpr
  name: GDPR
  evidence: GDPR readiness claimed on the DoControl website.
  source: https://www.docontrol.io/
programme:
  page: https://www.docontrol.io/security
  page_status: 200
  page_machine_readable: false
  page_note: >-
    Webflow, client-rendered. HTTP 200 and 120KB of HTML, but the certification names are not in
    the served markup — a crawler reading only the response body sees none of them.
  contact: security@docontrol.io
  practices:
  - Penetration testing
  - Publicly available self-assessments
  - Data processing addendum
  - Information Security Policy
  data_handling:
    llm_use_disclosed: true
    llm_statement: >-
      DoControl discloses that it uses LLMs for global search, alerts and its Dot assistant, that
      the models are hosted inside DoControl's own environment with no internet access, and that
      customer data is never sent to, stored by, or used to train any external LLM or AI service.
    source: https://docs.docontrol.io/docontrol-user-guide/getting-started/overview/security-privacy-and-compliance.md
trust_center:
  dedicated_portal: false
  note: >-
    No Vanta/Drata/SafeBase-style trust portal; trust.docontrol.io does not resolve. Evidence is a
    marketing page plus a documentation page, with no downloadable report index.
evidence:
- source: https://docs.docontrol.io/docontrol-user-guide/getting-started/overview/security-privacy-and-compliance.md
  status: 200
  keywords:
  - iso 27001
  - soc2 type ii
  - penetration testing
  - self-assessments
  - data processing addendum
- source: https://www.docontrol.io/
  status: 200
  keywords:
  - hipaa
  - gdpr

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/docontrol-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.