Privacy Policy
Last updated: 28 February 2026
1. Who We Are
DoksOps ("we", "us", "our") is an automated infrastructure documentation platform. We scan AWS accounts using read-only API calls and generate professional documentation, diagrams, and compliance reports.
2. Data We Collect
2.1 Account Information
When you sign up, we collect your name, email address, and authentication details (via GitHub OAuth, Google OAuth, or email/password). If you create an organization, we store the organization name and team member roles.
2.2 AWS Infrastructure Metadata
When you run a scan, we collect infrastructure metadata only — resource configurations, counts, types, and settings. We use exclusively Describe*, List*, and Get* API calls (166 read-only IAM actions across 86 AWS services). We never:
- Read the contents of S3 objects, databases, or secrets
- Access application data, user data, or PII stored in your infrastructure
- Write, modify, or delete any resources in your AWS account
- Use Cost Explorer on your account (pricing lookups use our own AWS account)
2.3 Generated Documents
Documents, diagrams, and compliance reports generated from your scans are stored in your organization's workspace. These contain infrastructure metadata, AI-generated analysis, and compliance assessments.
2.4 Usage Data
We track scan counts and feature usage for plan enforcement and product improvement. We do not use third-party analytics trackers.
3. How We Use Your Data
- Generate documentation, diagrams, and compliance reports from your infrastructure metadata
- Provide AI-enriched analysis using a Mistral LLM that runs only in the EU — by default on AWS Bedrock (locked to EU regions at the IAM level), or on a self-hosted model for Enterprise — your metadata is not sent to any LLM outside the EU, nor to any third-party AI provider
- Enforce plan limits (scan quotas, seat counts, feature access)
- Send transactional emails (scan completed, team invitations, password resets)
- Improve the product based on aggregate, anonymized usage patterns
4. Data Storage & Security
- All data is stored in encrypted databases with access controls
- AWS credentials you provide are encrypted at rest and used only during scans
- Scan results and generated documents are isolated per organization
- We do not sell, share, or provide your infrastructure data to any third party
- AI enrichment runs only on EU-region infrastructure — AWS Bedrock (Mistral, EU-only, enforced at the IAM level) or a self-hosted model — and no data is sent to OpenAI, Anthropic, or any LLM outside the EU
5. Data Retention
Scan results and generated documents are retained for the lifetime of your account unless you delete them. You can delete individual scans, documents, or your entire organization at any time from the Settings page. Upon account deletion, all associated data is permanently removed within 30 days.
6. Third-Party Services
We use the following third-party services:
- GitHub & Google OAuth — for authentication (we receive your name, email, and profile picture)
- Stripe — for payment processing (we do not store credit card details)
- AWS Pricing API — queried from our own account for cost estimation (no cost to you)
7. Your Rights
You can at any time:
- Export your scan data and generated documents
- Delete individual scans, documents, or your entire account
- Revoke AWS credentials from the Settings page
- Request a copy of all data we hold about you
For GDPR, CCPA, or other data protection requests, contact us at privacy@doksops.com.
8. Cookies
We use essential cookies only — session authentication and CSRF protection. We do not use advertising, tracking, or analytics cookies.
9. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email to account holders. The "Last updated" date at the top reflects the most recent revision.
10. Contact
Questions about this privacy policy? Email privacy@doksops.com.