Your data is yours.
Here's how we protect it.
GembaDocs is SOC 2 Type II examined, GDPR compliant, and built on AWS with encryption and 24/7 monitoring. This page answers the questions we get asked most.
Four things worth knowing upfront
SOC 2 Type II examined
Independent audit covering security, availability, and confidentiality. Available under NDA on request.
GDPR compliant
UK and EU GDPR. Data Processing Agreement included with every customer. You remain the data controller.
Encrypted end to end
How we protect your data
Access control
Monitoring and testing
Standards
What we have
SOC 2 Type II examined
Independent AICPA-accredited audit – available under NDA on request.
Assessments
Passed dozens of Fortune 500 security assessments.
What we align with
ISO/IEC 27001:2022 (aligned, not certified). CIS Top 18 Controls – NIST AI RMF 1.0 – OWASP Top 10 – SANS Top 25 – UK and EU GDPR
As a business we are not ITAR certified, but with our on-premise version of GembaDocs, your organization will be able to comply with ITAR.
Fit for regulated manufacturing
Used by manufacturers operating under FDA, MHRA, EMA, ISO 13485, and ISO 9001 quality systems. Electronic records, controlled change history, segregation of duties, and audit trail integrity built in. Validation documentation (IQ/OQ/PQ, GAMP 5 risk-based) available on request.
FAQs
Where is my data stored?
GembaDocs is hosted on Amazon Web Services (AWS). Secondary backups are replicated to Google Cloud. Customers receive a written description of the specific regions used in the Data Processing Agreement. No data is processed outside of these documented environments.
Do you have a Data Processing Agreement?
Yes. A GDPR Article 28-compliant Data Processing Agreement (DPA) is available to all customers as part of standard terms. It covers data controller / processor responsibilities, sub-processor disclosure, standard contractual clauses for international transfers, and your rights as data controller. Contact us to request a copy.
Can I get a copy of your SOC 2 report?
Do you support Single Sign-On (SSO)?
What happens to my data if I leave GembaDocs?
Your data belongs to you. On written request after contract termination, GembaDocs will securely delete or anonymize your personal data. We do not retain customer data beyond what is needed to deliver the service. On our top plans, full data downloads can be requested on exit.
Is GembaDocs suitable for regulated industries?
Yes. GembaDocs is used by manufacturers operating under FDA, MHRA, EMA, ISO 13485, and ISO 9001 quality systems. The platform includes electronic records, controlled document versioning, segregation of duties, and audit trail integrity. Validation documentation to support IQ/OQ/PQ and GAMP 5 risk-based computer-system validation activities is available on request.
What security frameworks do you follow?
Our security programme aligns with CIS Top 18 Controls, NIST AI Risk Management Framework (AI RMF 1.0), ISO/IEC 27001:2022, OWASP Top 10, and SANS Top 25. We are SOC 2 Type II examined and UK and EU GDPR compliant. Independent quarterly penetration testing applies OWASP and SANS methodologies.
Who are your sub-processors?
Our current sub-processors are: Amazon Web Services (primary cloud infrastructure), Google Cloud (encrypted backup), and a transactional email provider. The full sub-processor list is included in the Data Processing Agreement. Customers are notified in advance of any material change.
What is your platform uptime commitment?
GembaDocs commits to 99.5% platform availability per calendar month under our published Service Level Agreement, excluding scheduled maintenance and force majeure events. Critical incidents affecting the full platform are responded to within 2 hours. High-priority issues are responded to within one business day.
How is my data separated from other customers on the platform?
GembaDocs is a multi-tenant cloud platform. Each customer’s data is logically segregated at both the application and database layers, with tenant scoping applied to every request. Your data is never accessible to other customers.
Still have questions?
Security questions are best answered in a direct conversation. Book a call with Tom and we can walk through your specific requirements, share our SOC 2 report under NDA, or answer anything your IT or compliance team needs.
