To deliver a resilient, high-speed, and secure document signing platform, Doccu engages trusted infrastructure sub-processors. All primary customer databases, credentials, and business metadata reside 100% in-country within the Republic of South Africa. Encrypted document binaries are stored within tier-1 enterprise facilities subject to strict adequacy safeguards under POPIA Section 72.
| Sub-processor | Location | Role & Activity | Data Transferred | Compliance Standard |
|---|---|---|---|---|
| xneelo (Pty) Ltd | South Africa (CPT / JHB) | Primary production compute, application servers, and relational PostgreSQL databases. | All primary application data and user records. | 100% In-Country Residency |
| Cloudflare, Inc. (Cloudflare R2) | European Union | Object storage for encrypted PDF document binaries and signed artifacts. | Encrypted PDF documents and evidence attachments. | POPIA s72(1)(a) Adequacy |
| PayFast (Pty) Ltd (Network International) | South Africa | Payment processing gateway, card tokenization, and instant EFT handling. | Billing details, transaction IDs, payer names. | PCI-DSS Level 1 |
| Resend, Inc. | United States / EU | Transactional email delivery for signing invitations and completion notices. | Signer email addresses, names, and invitation links. | SOC 2 Type II / TLS 1.3 |
| Functional Software, Inc. (Sentry) | United States | Real-time application crash telemetry and error reporting. | Application trace errors (sanitized by automated PII scrubber middleware). | PII Scrubbing Enforced |
| Aikido Security BV | European Union | Automated SAST/DAST application security and vulnerability assessments. | Code metadata and security scan telemetry (no customer PII transferred). | ISO 27001 / GDPR |
Doccu conducts thorough security diligence prior to engaging any sub-processor. All data transferred is encrypted using industry-standard protocols (TLS 1.3 in transit and AES-256 at rest), with minimal data sharing principles strictly enforced.
Doccu provides at least thirty (30) days advance written notice to account administrators prior to authorizing any new infrastructure sub-processor to process customer personal information. Customers may object to proposed changes on reasonable data protection grounds by contacting our Information Officer at legal@doccu.co.za.