---
sidebar_label: Security & Privacy
sidebar_position: 7
description: How DocJacket protects your transactions, documents, and client data — encryption, hosting, access controls, backups, and your privacy rights.
---

<!-- Canonical: https://help.docjacket.com/docs/getting-started/security-and-privacy -->
<!-- Source: docs/getting-started/security-and-privacy.md -->

# Security & Privacy

**Is DocJacket secure? Are my documents safe?** Yes. Real estate transactions carry sensitive client, document, and financial information, so keeping your documents and client data secure is core to how DocJacket is built. Your documents are encrypted, access is controlled, and your data stays private — DocJacket is a secure system for storing and sharing transaction documents.

This page summarizes how DocJacket keeps your documents and data secure and private; the full, authoritative details live on the [Security](https://www.docjacket.com/security) and [Privacy Policy](https://www.docjacket.com/privacy) pages.

## How DocJacket keeps your documents and data secure

- **Encryption everywhere.** All data is encrypted **in transit with TLS 1.3** and **at rest with AES-256**.
- **Enterprise-grade hosting.** Servers are located in the **United States** on enterprise-grade cloud infrastructure.
- **Isolated per organization.** Each organization's data is separated at the database level — your data is never mixed with another org's.
- **Role-based access.** Team members only see what their role allows, and agents only see the transactions they're assigned to. See [Understanding Roles](./understanding-roles.mdx).
- **Automatic backups** run daily with **35-day retention** and geo-redundant storage, so data can be restored to a point in time within the past month.
- **Immutable archive storage.** **Archived deals** are stored on immutable, non-erasable **WORM-compliant storage** (per California Code of Regulations § 2729), so records can't be altered or deleted after archiving. See [Audit Mode](../documents/audit-mode.mdx).
- **Secure billing.** Payments are handled by a **PCI DSS Level 1** certified payment provider — DocJacket never stores full card numbers.
- **Ongoing testing.** DocJacket performs annual penetration testing and commits to breach notification within 24 hours to affected users.

## What DocJacket does *not* do

DocJacket does **not** sell your data, share it with third parties for their own marketing, use it to train AI models, or access your account without authorization.

## Your data and your clients' data

- **Document sharing is controlled by you.** Client and agent access happens through [portal links](../client-portal/index.mdx) you send — recipients see only what you share, without needing a DocJacket account.
- **Sharing with transaction participants** (brokers, escrow/title) happens only with your explicit permission.

## Data retention

- **Active transactions** are retained while the deal is in process.
- **Closed transactions** are retained for **7 years**, per real estate record-keeping regulations.
- **If you cancel**, your data is kept for **30 days** so you can reactivate, then permanently deleted.

## Your privacy rights

You can request to **access, correct, delete, or export** your data at any time, and opt out of marketing. DocJacket responds to requests within **30 days**, and supports **GDPR** (access, rectification, erasure, restriction, objection, portability) and **CCPA** (disclosure, deletion, do-not-sell) rights.

For privacy requests or questions, contact **privacy@docjacket.com** or **(407) 201-9147**, and review the full [Privacy Policy](https://www.docjacket.com/privacy).

:::note Sharing this with a client
If a client or agent asks whether DocJacket is secure, you can point them to the public [Security](https://www.docjacket.com/security) and [Privacy](https://www.docjacket.com/privacy) pages — they don't need an account to read them.
:::
