Security architecture & data residency
DocChat provides institutional-grade document exchange infrastructure engineered specifically for UAE financial institutions operating under Central Bank governance frameworks.
Data residency in Microsoft Azure UAE North
Customer documents and records are stored in Microsoft Azure UAE North.
All primary operational components—including object storage, relational databases, cryptographic audit ledgers, and key management services—are hosted within the Microsoft Azure UAE North cloud region located in Dubai, United Arab Emirates.
Sub-processors schedule & geographic distribution
To deliver resilient, global-standard infrastructure alongside specialized communications services, DocChat engages the following vetted sub-processors:
| Sub-processor | Service role | Data processing location | Data scope |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, blob storage, database, key management | UAE North (Dubai) | Customer documents, database records, audit ledgers, encryption keys |
| Resend | Transactional email notification delivery | AWS ap-northeast-1 (Tokyo, Japan) | Recipient email addresses, notification delivery tokens (no document contents) |
| SMSGlobal | SMS link delivery & OTP dispatch | Australia | Recipient mobile numbers, SMS delivery tokens, one-time verification codes |
| Cloudflare | Content delivery network (CDN), DNS resolution, DDoS protection, WAF | Global edge locations | Encrypted network transit traffic and IP metadata |
Note: While primary document storage and database records reside strictly in Azure UAE North, transactional communication notifications (SMS and email) are processed via regional and international delivery partners.
Technical controls & encryption architecture
DocChat enforces defense-in-depth controls across every tier of the application:
1. Encryption in transit & at rest
All network traffic between clients, staff consoles, and API gateways is encrypted using TLS. Documents stored in Azure Blob Storage and records in PostgreSQL are encrypted at rest using AES-256 with keys managed through Azure Key Vault.
2. SHA-256 cryptographic audit chain
Every state-changing event—including document requests, uploads, verification scans, operator reviews, and customer downloads—is recorded with a SHA-256 cryptographic hash. Each record incorporates the previous event's hash, forming an immutable chain whose root is anchored in Azure Key Vault.
3. Multi-tenant data isolation
Tenant data is strictly separated at the database layer using PostgreSQL Row-Level Security (RLS) policies. Every SQL query is automatically scoped to the authenticated tenant context, preventing cross-institution data access.
4. Automated anti-malware scanning
All uploaded files undergo automated anti-malware scanning before being decrypted or made accessible in staff review queues. Suspicious files are automatically quarantined and flagged.
Governance alignment
DocChat is architected to support institutions in fulfilling their compliance obligations under:
- CBUAE Circular CBUAE/MCS/2026/2058: Structured customer communications and document governance.
- UAE Federal Decree-Law No. 45 of 2021 (PDPL): UAE Personal Data Protection Law requirements.
- DIFC Data Protection Law No. 5 of 2020: Data controller and processor obligations in the Dubai International Financial Centre.
Inquiries & security assessments
For compliance teams conducting vendor risk assessments or requesting security questionnaire packages, contact our security team: