Trust Center

Everything your security review needs, in one place.

Doclave manages access to documents in your Microsoft 365 tenant. Here is how we connect, what we hold, and the documents your team will ask for.

Contact our security team

Last reviewed: October 2026

01 — At a glance

The short version.

Documents

Your documents stay in your tenant.

Doclave manages access. Documents never leave Microsoft 365.

Hosting

Run from the EU.

Hosted in EU data centres and backed up on a 3-2-1 model.

Logs

Reference IDs, not names.

Logs hold reference IDs, never names or email addresses.

History

Protected against edits.

Every access change is recorded and can't be altered afterwards.

Visibility

Sensitive details hidden by default.

Only users with the right role can reveal sensitive data.

Partner

Approved Microsoft partner.

Coming to AppSource.

04 — Documents

The documents your team will ask for.

Public documents are linked below. Contract documents are shared when we agree terms.

Public

Privacy Policy

How we handle personal data.

Available

Cookie Policy

The cookies this website uses.

Available

With your agreement

Data Processing Agreement

Our commitments as your data processor.

With your agreement

Terms of Service

The terms for using Doclave.

With your agreement

05 — Our own security posture

Where we stand, and where we're going.

In place

Hosted on Microsoft Azure in the EU, backed up on a 3-2-1 model

Encrypted in transit (TLS 1.2+) and at rest (AES-256)

Multi-factor authentication on all administrative access

Least privilege: we never request full control of all sites. Doclave grants read or write to individual folders only

Access history protected against edits

Planned

Microsoft publisher verification, before launch

Independent penetration test

Doclave supports alignment. It doesn't replace your legal, security or compliance obligations.

Ready to see your own environment?

Run a readiness assessment and share this page with your IT lead.