Your data is yours.
Here's how we protect it.

GembaDocs is SOC 2 Type II examined, GDPR compliant, and built on AWS with encryption and 24/7 monitoring. This page answers the questions we get asked most.

Four things worth knowing upfront

SOC 2 Type II examined

Independent audit covering security, availability, and confidentiality. Available under NDA on request.

GDPR compliant

UK and EU GDPR. Data Processing Agreement included with every customer. You remain the data controller.

Encrypted end to end

TLS 1.2+ in transit, AES-256 at rest. Backups encrypted and retained for 30 days.

Hosted on AWS

Primary on Amazon Web Services. Secondary backups on Google Cloud. Hourly backups, 99.5% uptime SLA.

How we protect your data

Access control

MFA enforced for all admin access and available to every user. Role-based access control across app, database, and infrastructure. SSO via SAML 2.0 available for enterprise customers (Microsoft Entra / Azure AD). User access reviewed quarterly – leavers removed the same day.

Monitoring and testing

Quarterly independent penetration testing (OWASP Top 10, SANS Top 25). Monthly vulnerability scanning. 24/7 Security Operations Centre monitoring with enterprise threat-intelligence feeds. Clean operational record – no reportable data breaches in five years.

Audit trails

Every change to an SOP or controlled document is captured with user identity, action, timestamp, and outcome. Audit logs are centralized, tamper-resistant, and monitored. This supports FDA 21 CFR Part 11 and EU GMP Annex 11 audit-trail expectations.

Standards

What we have

SOC 2 Type II examined

Independent AICPA-accredited audit – available under NDA on request.

Assessments

Passed dozens of Fortune 500 security assessments.

What we align with

ISO/IEC 27001:2022 (aligned, not certified). CIS Top 18 Controls – NIST AI RMF 1.0 – OWASP Top 10 – SANS Top 25 – UK and EU GDPR

As a business we are not ITAR certified, but with our on-premise version of GembaDocs, your organization will be able to comply with ITAR.

Fit for regulated manufacturing

Used by manufacturers operating under FDA, MHRA, EMA, ISO 13485, and ISO 9001 quality systems. Electronic records, controlled change history, segregation of duties, and audit trail integrity built in. Validation documentation (IQ/OQ/PQ, GAMP 5 risk-based) available on request.

FAQs

Where is my data stored?

GembaDocs is hosted on Amazon Web Services (AWS). Secondary backups are replicated to Google Cloud. Customers receive a written description of the specific regions used in the Data Processing Agreement. No data is processed outside of these documented environments.

Yes. A GDPR Article 28-compliant Data Processing Agreement (DPA) is available to all customers as part of standard terms. It covers data controller / processor responsibilities, sub-processor disclosure, standard contractual clauses for international transfers, and your rights as data controller. Contact us to request a copy.

Yes. GembaDocs has completed a SOC 2 Type II examination by an independent AICPA-accredited firm, covering the security, availability, and confidentiality of the service. The report is available under NDA to customers and qualified prospects. [Contact us to request it.]
Yes. Enterprise customers can federate sign-in using their own identity provider via SAML 2.0. Compatible with Microsoft Entra (Azure AD) and other SAML 2.0 identity providers. [Contact us] to set this up for your organization.

Your data belongs to you. On written request after contract termination, GembaDocs will securely delete or anonymize your personal data. We do not retain customer data beyond what is needed to deliver the service. On our top plans, full data downloads can be requested on exit.

Yes. GembaDocs is used by manufacturers operating under FDA, MHRA, EMA, ISO 13485, and ISO 9001 quality systems. The platform includes electronic records, controlled document versioning, segregation of duties, and audit trail integrity. Validation documentation to support IQ/OQ/PQ and GAMP 5 risk-based computer-system validation activities is available on request.

Our security programme aligns with CIS Top 18 Controls, NIST AI Risk Management Framework (AI RMF 1.0), ISO/IEC 27001:2022, OWASP Top 10, and SANS Top 25. We are SOC 2 Type II examined and UK and EU GDPR compliant. Independent quarterly penetration testing applies OWASP and SANS methodologies.

Our current sub-processors are: Amazon Web Services (primary cloud infrastructure), Google Cloud (encrypted backup), and a transactional email provider. The full sub-processor list is included in the Data Processing Agreement. Customers are notified in advance of any material change.

GembaDocs commits to 99.5% platform availability per calendar month under our published Service Level Agreement, excluding scheduled maintenance and force majeure events. Critical incidents affecting the full platform are responded to within 2 hours. High-priority issues are responded to within one business day.

GembaDocs is a multi-tenant cloud platform. Each customer’s data is logically segregated at both the application and database layers, with tenant scoping applied to every request. Your data is never accessible to other customers.

Still have questions?

Security questions are best answered in a direct conversation. Book a call with Tom and we can walk through your specific requirements, share our SOC 2 report under NDA, or answer anything your IT or compliance team needs.