Security & Compliance FAQ
Status Legend
Symbol
Meaning
🔹 Data Location & Residency
1. Where exactly is the production environment hosted?
2. Where is the DR (Disaster Recovery) environment hosted?
3. Where are backups stored?
4. Are there geo-partitioning options (e.g., UK-only)?
5. Is data encrypted at rest and in transit?
🔹 AI/ML Model Handling
6. Are invoice contents sent to any third-party model host (e.g., OpenAI, Azure AI)?
7. Are extracted documents used to train broader models across customers?
8. Can you restrict model training to your tenant only?
9. Where are AI/ML models hosted and executed?
10. What AI/ML technologies are used (OCR engine, LLM, NLP)?
11. Is there an option for on-premise AI model deployment?
🔹 Data Access & Logging
12. Who (vendor support/engineers) can access raw documents and Infor LN data?
13. What access controls and logging exist for vendor personnel?
14. How long are access logs retained?
15. How long are uploaded documents / extracted data retained in DocBits?
16. Can customers request data deletion on demand?
17. What subprocessors have access to customer data?
18. What certifications and compliance frameworks does DocBits hold?
🔹 Integration Scope (Infor LN)
19. What is the exact list of data fields pulled from LN masters for validation?
20. What specific header fields are exported back to LN?
21. Are write-back operations scoped only to AP/PO interface objects?
22. What integration method is used (ION API, BODs, direct DB)?
23. What authentication/authorization is used for LN connectivity?
24. Is data transfer between DocBits and LN encrypted end-to-end?
25. What document types are supported beyond AP invoices?
Last updated
Was this helpful?