UAE Banking & Financial InstitutionsCBUAE Circular CBUAE/MCS/2026/2058

Two-way document exchange built for UAE financial institutions.

DocChat collects and delivers customer records through single-use, verified links. Eliminate WhatsApp and email attachments with end-to-end audit trails and complete UAE data residency.

UAE data residencyAzure UAE North (Dubai)
Tamper-evident auditSHA-256 chained logs
Two-way exchangeInbound KYC & outbound delivery
app.docchat.co/exchange
Active
Exchange activity

Inbound verification and outbound document delivery

KYC
Emirates ID & proof of address
Inbound · SMS OTP verified
Uploaded
DOC
Trade license & memorandum
Inbound · Malware scanned
Verified
OUT
Facility offer agreement · PDF
Outbound · Signed dispatch
Delivered
Audit entry:sha256:7f83b1657ff1fc53b92dc18148a1d65dfc2d4b1f...
Regulated sectors

Designed for UAE financial institutions.

From DIFC and ADGM asset managers to national commercial banks and exchange houses, DocChat provides compliant document exchange workflows.

Commercial & retail banks

Customer KYC verification, account opening requirements, and lending documentation.

Insurance companies

Policy endorsement records, medical disclosures, and claims verification files.

Foreign exchange houses

Remittance beneficiary verification and source of funds declarations.

Finance & leasing companies

Asset financing applications, trade licenses, and board resolutions.

Payment service providers

Merchant onboarding underwriting and corporate entity documentation.

Wealth & asset managers

Investor onboarding, FATCA/CRS forms, and confidential portfolio statements.

Platform capabilities

Engineered for regulated financial workflows.

DocChat replaces unmonitored consumer chat channels and email attachments with a structured, auditable document exchange workflow.

Zero installation

No apps or logins for customers

Customers open a secure link from SMS or email, capture their documents with their device camera, and submit in seconds. No account registration or mobile app required.

Mobile browser camera capture
Data residency

Stored in Azure UAE North

Customer documents and records are stored in Microsoft Azure UAE North. Built to support obligations under UAE Personal Data Protection Law and CBUAE governance expectations.

Azure UAE North region
Tamper-evident log

Verifiable audit evidence

Every document request, submission, scan result, and delivery is cryptographically chained using SHA-256 with an HSM-signed root in Azure Key Vault.

Exportable audit packages
Two-way exchange

Collect and deliver securely

Collect inbound customer files with structured field requirements or deliver confidential documents via secure, time-limited verification links.

Inbound KYC & outbound delivery
30 Apr 2026
Compliance deadline
CBUAE/MCS/2026/2058 circular requirements for regulated entities.
UAE North
Data residency
Customer documents and records stored in Microsoft Azure UAE North.
SHA-256
Tamper-evident chain
Cryptographic hash chaining with HSM-backed root signing in Key Vault.
Two-Way
Secure exchange
Branded document request links and confidential outbound delivery.
Regulator inspection proof

Complete audit trails for regulator inspection.

Every document request, customer submission, and staff approval is recorded in an immutable ledger. When examiners or internal auditors request evidence, export verified packages in seconds.

  • Chronological event trail with operator attribution and UTC timestamps
  • SHA-256 cryptographic verification of all uploaded files and events
  • One-click audit export formatted for CBUAE and internal compliance inspection
  • Tamper-evident chain root signed with Azure Key Vault HSM protection
SHA-256 Cryptographic Audit Chain StructureSequential audit blocks linked via SHA-256 payload hashes and anchored in Azure Key Vault HSM root signing.IMMUTABLE AUDIT LEDGER · SHA-256 HASH CHAINLIVEBLOCK 1041Event: REQ_CREATEDTime: 14:02:11 UTCPREV HASH:0x4f8a9e12...BLOCK HASH:0x7a3c89b4...✓ Genesis linkedBLOCK 1042Event: DOC_UPLOADEDTime: 14:04:45 UTCPREV HASH:0x7a3c89b4...BLOCK HASH:0xe2d140a8...✓ Chained SHA-256BLOCK 1043Event: DOC_DELIVEREDTime: 14:05:02 UTCPREV HASH:0xe2d140a8...ROOT SIGNATURE:Azure Key Vault HSM✓ Non-repudiationCryptographically chained per RFC 8785 canonical JSON · Exportable regulator evidence package
Inbound collection

Structured, verified customer document collection.

Staff generate requests in seconds. Customers open a secure link, snap documents from any browser, and submissions arrive in your queue with complete audit attribution.

  • Standardized document templates with required KYC and operational fields
  • Delivery of secure, time-limited upload links via SMS and email
  • Mobile browser capture from any smartphone device without app installation
  • Automated malware scanning before files enter institution review queues
Inbound Document Collection WorkflowStep 1: Institutional Request. Step 2: Customer Link and OTP Verification. Step 3: Direct Mobile Browser Upload. Step 4: Azure UAE North Sovereign Vault and SHA-256 Audit Entry.INBOUND KYC & DOCUMENT COLLECTION WORKFLOWTLS ENCRYPTED1Institution Request• Officer selects pre-approved template• Defines required KYC checklist• Dispatches time-limited token link2Customer Verification• Branded SMS / email link received• Single-use OTP challenge verified• Zero app installation or passwords3Direct Mobile Upload• Smartphone camera document snap• Automated file format validation✓ Automated anti-malware scan4Azure UAE North Vault• AES-256 encrypted blob storage• SHA-256 chained audit block logged• Ready for staff queue review
Outbound Document Delivery WorkflowStep 1: Document Dispatch. Step 2: Encrypted Link Delivery. Step 3: Recipient Identity Verification. Step 4: Tamper-Evident Download and Audit Ledger Receipt.OUTBOUND CONFIDENTIAL DOCUMENT DELIVERY WORKFLOWNON-REPUDIATION1Document Dispatch• Staff attaches facility offer / contract• Sets token TTL & access permissions• Logs dispatch hash to audit ledger2Secure Notification• Branded SMS / email notification• Time-limited single-use token URL• Zero confidential data in clear text3Recipient Step-Up OTP• Mandatory 6-digit verification code• Strict rate-limit attempt gating✓ Authenticated recipient session4Verified Delivery Receipt• Direct TLS Azure UAE North fetch• Recipient download confirmed• Immutable proof-of-delivery seal
Outbound delivery

Send confidential files with verified proof of delivery.

Relationship managers and operations staff deliver sensitive contracts, sanction letters, and statements. Customers verify identity before viewing, creating an auditable delivery receipt.

  • Single-use, time-limited download links with automated expiry
  • Delivery notification via SMS and corporate email
  • Identity verification challenge required before customer file access
  • Immutable delivery receipts with exact timestamp and operator attribution
Customer experience

Zero friction for customers — no app or account creation needed.

Customers receive a secure link via SMS or email, complete identity verification, and upload requested documents in minutes from any device.

  • Web-based interface — opens on any modern smartphone or desktop browser
  • Arabic (RTL) and English (LTR) language support
  • Institution branding with custom logo and color accents
  • Direct camera capture and file upload without app store downloads
Financial institution portal

Submit requested documents

Please provide the requested documents to complete your verification.

Emirates ID (front & back)Uploaded · Scanned
Proof of residential addressUploaded · PDF
+
Salary certificate / statementTap to capture / upload
Submit documents →
Regulatory context

Aligned with CBUAE Circular CBUAE/MCS/2026/2058.

Issued 17 April 2026 with an enforceable compliance deadline of 30 April 2026. DocChat supports licensed financial institutions in eliminating unmonitored consumer chat channels for customer document exchange.

01

Sovereign data residency

Customer documents and records are stored in Microsoft Azure UAE North. Private network transit and encryption at rest with tenant-isolated database rows.

02

Tamper-evident audit chain

Every request, upload, verification, and document delivery is cryptographically chained using SHA-256 with an HSM-signed root in Azure Key Vault.

03

Structured governance

Pre-approved document request templates, mandatory field enforcement, role-based access controls, and automatic time-based expiry windows.

Transparent pricing

Simple, predictable institutional plans.

Flat annual subscriptions in UAE Dirhams (AED) with complete document collection, delivery, and audit capabilities included.

Standard

Standard

For finance teams and boutique advisory firms modernizing document collection.

AED99/ user / month
Billed annually (AED 1,188 / user / yr)
5 GB storage per user per year
  • Inbound document collection links
  • Outbound document delivery links
  • SHA-256 tamper-evident audit ledger
  • Automated SMS and email link delivery
  • Automated malware scanning
  • Microsoft Azure UAE North residency
Enterprise

Enterprise

For institutions requiring custom volume, dedicated infrastructure, and tailored agreements.

Contact sales
Tailored user volume & storage SLAs
Custom storage allocation
  • Tailored user seats and quotas
  • Custom domain and custom email routing
  • Tailored Data Processing Addendum (DPA)
  • Dedicated technical account contact
  • Azure Key Vault dedicated HSM integration
All plans billed annually. Customer documents and audit records are retained for the duration of an active contract in Microsoft Azure UAE North.
Frequently asked questions

Common questions about DocChat.

Answers about compliance alignment, data residency, customer experience, and security controls.

DocChat helps UAE financial institutions eliminate unmonitored consumer messaging channels for customer document exchange. The platform provides tamper-evident audit trails with SHA-256 cryptographic chaining, Azure UAE North residency, automated malware scanning, and exportable evidence packages.

Customer documents and records are stored in Microsoft Azure UAE North. Files are encrypted in transit and at rest, and tenant data is strictly partitioned using PostgreSQL row-level security.

DocChat captures every document request, customer submission, and staff decision in an append-only cryptographic ledger. Each entry is hashed with SHA-256 and linked to the previous block, anchored to an HSM-backed root key in Azure Key Vault.

No. Customers receive a secure time-limited link via SMS or email. The upload portal runs in any modern smartphone or desktop browser with direct camera capture. No app download or password creation is required.

Staff can package confidential documents (such as sanction letters, statements, or agreements) and generate a secure delivery link. The recipient verifies identity via one-time code before viewing, and proof of access is logged into the audit ledger.

DocChat uses Microsoft Azure for core hosting, database, and document storage in UAE North; Resend for transactional email notifications (AWS ap-northeast-1, Japan); SMSGlobal for SMS link delivery (Australia); and Cloudflare for edge security, DNS, and WAF.

Institution onboarding

Ready to modernize your customer document workflow?

DocChat is currently onboarding an initial cohort of design partners among UAE financial institutions.

✓ Azure UAE North data residency✓ CBUAE governance alignment✓ SHA-256 tamper-evident audit ledger