Security architecture & data residency

DocChat provides institutional-grade document exchange infrastructure engineered specifically for UAE financial institutions operating under Central Bank governance frameworks.

Data residency in Microsoft Azure UAE North

Customer documents and records are stored in Microsoft Azure UAE North.

All primary operational components—including object storage, relational databases, cryptographic audit ledgers, and key management services—are hosted within the Microsoft Azure UAE North cloud region located in Dubai, United Arab Emirates.

Sub-processors schedule & geographic distribution

To deliver resilient, global-standard infrastructure alongside specialized communications services, DocChat engages the following vetted sub-processors:

Sub-Processor Physical Location & Data Residency ArchitecturePhysical data distribution: Microsoft Azure in UAE North (Dubai) for primary documents and databases; Resend in Tokyo Japan for transactional emails; SMSGlobal in Australia for SMS dispatch; Cloudflare for global edge protection.SUB-PROCESSOR GEOGRAPHIC MAPPING & DATA SCOPETRANSPARENTMicrosoft Azure (UAE North)Location: Dubai, United Arab Emirates• Customer documents & KYC files• PostgreSQL database & audit ledgers• Azure Key Vault HSM keys✓ In-Region Data Residency2Cloudflare (Global Edge)Location: Distributed Edge Nodes• Edge TLS termination & DDoS shielding• Web Application Firewall (WAF)• Zero clear-text document storage3Resend (Transactional Email)Location: AWS Tokyo, Japan• Delivery notification dispatches• Email access token transmission• No customer documents transferred4SMSGlobal (SMS Link & OTP)Location: Melbourne, Australia• Recipient mobile phone routing• Single-use SMS OTP passcodes• International telecom egress disclosure
Sub-processorService roleData processing locationData scope
Microsoft AzureCloud infrastructure, blob storage, database, key managementUAE North (Dubai)Customer documents, database records, audit ledgers, encryption keys
ResendTransactional email notification deliveryAWS ap-northeast-1 (Tokyo, Japan)Recipient email addresses, notification delivery tokens (no document contents)
SMSGlobalSMS link delivery & OTP dispatchAustraliaRecipient mobile numbers, SMS delivery tokens, one-time verification codes
CloudflareContent delivery network (CDN), DNS resolution, DDoS protection, WAFGlobal edge locationsEncrypted network transit traffic and IP metadata

Note: While primary document storage and database records reside strictly in Azure UAE North, transactional communication notifications (SMS and email) are processed via regional and international delivery partners.

Technical controls & encryption architecture

DocChat enforces defense-in-depth controls across every tier of the application:

1. Encryption in transit & at rest

All network traffic between clients, staff consoles, and API gateways is encrypted using TLS. Documents stored in Azure Blob Storage and records in PostgreSQL are encrypted at rest using AES-256 with keys managed through Azure Key Vault.

2. SHA-256 cryptographic audit chain

Every state-changing event—including document requests, uploads, verification scans, operator reviews, and customer downloads—is recorded with a SHA-256 cryptographic hash. Each record incorporates the previous event's hash, forming an immutable chain whose root is anchored in Azure Key Vault.

SHA-256 Cryptographic Audit Chain StructureSequential audit blocks linked via SHA-256 payload hashes and anchored in Azure Key Vault HSM root signing.IMMUTABLE AUDIT LEDGER · SHA-256 HASH CHAINLIVEBLOCK 1041Event: REQ_CREATEDTime: 14:02:11 UTCPREV HASH:0x4f8a9e12...BLOCK HASH:0x7a3c89b4...✓ Genesis linkedBLOCK 1042Event: DOC_UPLOADEDTime: 14:04:45 UTCPREV HASH:0x7a3c89b4...BLOCK HASH:0xe2d140a8...✓ Chained SHA-256BLOCK 1043Event: DOC_DELIVEREDTime: 14:05:02 UTCPREV HASH:0xe2d140a8...ROOT SIGNATURE:Azure Key Vault HSM✓ Non-repudiationCryptographically chained per RFC 8785 canonical JSON · Exportable regulator evidence package

3. Multi-tenant data isolation

Tenant data is strictly separated at the database layer using PostgreSQL Row-Level Security (RLS) policies. Every SQL query is automatically scoped to the authenticated tenant context, preventing cross-institution data access.

Multi-Tenant Row-Level Security (RLS) Isolation ArchitectureSeparate institutional lanes for Bank A, Bank B, and Insurance C passing through authenticated tenant contexts to an isolated PostgreSQL database with cryptographic RLS policies.POSTGRESQL ROW-LEVEL SECURITY (RLS) DATA ISOLATIONZERO LEAKAGEInstitution A (Bank)tenant_id = 't_bank_01'Isolated Context AInstitution B (Insurance)tenant_id = 't_ins_02'Isolated Context BInstitution C (Exchange)tenant_id = 't_exch_03'Isolated Context CRLS SecurityGatewaySET LOCALapp.current_tenantPOLICY CHECKWHERE tenant_id= current_settingEnforced atDatabase LayerAzure PostgreSQL (UAE North)Bank A KYC RecordsRow level isolatedInsurance B PoliciesRow level isolatedExchange C RemittanceRow level isolatedAES-256 StorageZero cross-tenant visibility

4. Automated anti-malware scanning

All uploaded files undergo automated anti-malware scanning before being decrypted or made accessible in staff review queues. Suspicious files are automatically quarantined and flagged.

Governance alignment

DocChat is architected to support institutions in fulfilling their compliance obligations under:

  • CBUAE Circular CBUAE/MCS/2026/2058: Structured customer communications and document governance.
  • UAE Federal Decree-Law No. 45 of 2021 (PDPL): UAE Personal Data Protection Law requirements.
  • DIFC Data Protection Law No. 5 of 2020: Data controller and processor obligations in the Dubai International Financial Centre.

Inquiries & security assessments

For compliance teams conducting vendor risk assessments or requesting security questionnaire packages, contact our security team:

Contact security & compliance team →