The controls behind each guest compliance session.

DocinVault is a Georgian company building guest compliance infrastructure for hospitality. This page explains what we protect, how the service is operated, which providers support it, and where customers can request more detail.

Hospitality infrastructure from Georgia

DocinVault LLC builds the agentic compliance operations layer for regulated hospitality. The service connects guest collection, configured checks, routine follow-up, structured output, and booking-linked evidence.

Identity data and the workflow around it

Our controls cover guest identity evidence, booking-linked sessions, workflow status, audit history, customer configuration, and access by authorized operator roles.

Practical security controls.

Security is applied to the session, the information returned to an operator, and the people and systems allowed to use it.

01

Encryption in transit and at rest

Guest sessions use encrypted transport. Stored protected data is encrypted at rest through managed infrastructure controls.

02

Role-based access

Unique user accounts, least privilege, strong authentication, and access review limit who can use sensitive functions and information.

03

Session isolation

Guest evidence and decisions remain connected to the intended booking and workflow rather than being shared through routine staff channels.

04

Booking-linked audit history

Configured consent, timestamps, status changes, access, and review actions can be recorded against the relevant session.

05

Configurable retention

Retention and deletion follow the customer's documented instructions, configured period, contract, and applicable obligations.

06

Restricted raw-document access

Operators receive the approved status and structured fields they need. Raw-document access is restricted and logged by default.

Hosted on AWS under a shared-responsibility model.

DocinVault uses Amazon Web Services EMEA SARL for primary cloud infrastructure and data processing in the European Economic Area. Google Cloud EMEA Limited supports backup and restoration, with relevant servers in Frankfurt, Germany.

AWS protects the underlying cloud infrastructure. DocinVault remains responsible for its application, customer data, access configuration, encryption choices, and secure use of the services it selects.

Designed to support customer privacy obligations.

DocinVault applies privacy, access, retention, data-subject request, and incident processes designed to support obligations under the Law of Georgia on Personal Data Protection and the GDPR where applicable.

Customers remain responsible for the purpose and lawful basis of each workflow, the fields and checks they enable, authorized users, retention, local reporting, and notices presented to guests.

A data processing agreement and current subprocessor information are available during customer review. This page is an operational overview, not legal advice or a claim of universal compliance.

A practical control map for the system we operate.

These frameworks organize DocinVault's internal control baseline. This is a control mapping, not certification by the framework publishers.

NIST CSF 2.0

Risk structure

NIST Cybersecurity Framework 2.0

Govern, Identify, Protect, Detect, Respond, and Recover organize ownership and security-risk decisions.

CIS IG1

Security hygiene

CIS Critical Security Controls Implementation Group 1

A prioritized checklist for foundational inventory, access, configuration, vulnerability, recovery, and awareness controls.

OWASP ASVS 5.0

Application and API catalog

OWASP Application Security Verification Standard 5.0

A review catalog for authentication, access control, validation, cryptography, APIs, data, and secure application behavior.

NIST AI RMF

Agentic-plane governance

NIST AI Risk Management Framework

Govern, Map, Measure, and Manage frame agent authority, observed behavior, risk evaluation, and intervention.

Providers that support service delivery.

The exact providers and processing arrangement for a customer deployment are governed by the applicable agreement and configuration.

Amazon Web Services EMEA SARL

Purpose
Primary cloud infrastructure and data processing
Processing location
European Economic Area
Relevant data
Customer content, application data, technical and security records

Google Cloud EMEA Limited

Purpose
Backup and restoration for the AWS-hosted environment
Processing location
Frankfurt, Germany
Relevant data
Encrypted backup content and related technical records

Cloudflare, Inc.

Purpose
Network delivery, traffic routing, availability, and security
Processing location
Global network, subject to contractual safeguards
Relevant data
IP addresses, routing data, configuration, and traffic information

Resend

Purpose
Delivery of public contact-form messages
Processing location
Subject to Resend's applicable service and transfer terms
Relevant data
Business contact details and inquiry content

What we can share, and what we do not claim.

Available on request

  • Security and architecture overview appropriate to the proposed workflow
  • Data processing agreement
  • Current subprocessor information
  • Retention, access, and incident-response information relevant to the deployment

Current assurance boundary

  • DocinVault does not currently display formal third-party certification or named laboratory-assessment claims.
  • Formal assurance work will be selected as customer and regulatory needs justify its cost and scope.
  • A penetration-test summary will be offered only after a current independent assessment, remediation, and retest support that disclosure.

Security material available on request under NDA.

Qualified customer and procurement reviews can receive deeper material appropriate to the proposed deployment and confidentiality level.

  • System and data-flow diagrams
  • Data processing agreement
  • Access and retention schedules
  • Subprocessor and infrastructure detail
  • Incident-response and continuity overview
  • AI control-plane and human-oversight description

Reliability is defined around the guest and operator workflow.

Customer-specific service levels are agreed in the applicable contract. These operational objectives show what the service is instrumented to observe and protect.

Session creation

Requests accepted or rejected explicitly

Monitor successful creation, validation failures, idempotent replays, and latency.

Guest flow availability

The guest can complete the configured journey

Observe browser-flow reachability, step completion, retries, and service dependencies.

Result-delivery latency

Outcomes reach connected systems predictably

Measure event creation, signed webhook attempts, acknowledgements, retries, and final delivery state.

Report a suspected security issue directly.

Send a clear description, affected URL or component, reproduction steps, and the potential impact to contact@docinvault.com. Please avoid accessing data that is not yours, disrupting service, or publicly disclosing an unresolved issue. We will acknowledge the report, assess it, and keep the reporter informed as the investigation allows.