Security
Candidate and employee documents contain sensitive data. Here's how doki.help helps collect them with more controlled access than ordinary chat.
Access is isolated at the database level (RLS) and limited by account, workspace, role, or the link granted.
Files live in a private bucket and are served only via short-lived signed links (about 2 minutes). A file has no public URL.
Share a single document, not the whole archive โ via a temporary link you can revoke anytime, cap by number of views, and mark with a watermark.
You can enable a second factor (TOTP). A new-device login triggers an email, so you notice unfamiliar access right away.
Every link-based document view is written to a log โ you can see what was opened and when.
Off by default. A document image is sent to an AI provider only if you turn recognition on yourself in settings. Don't want it โ your documents never leave for AI.
In secure cloud (Supabase infrastructure), transferred over HTTPS. Servers may be located outside Indonesia โ the cross-border transfer terms are set out in the Privacy Policy. We never sell or share your data for advertising.
You can export your documents from the cabinet at any time โ no lock-in. You delete your account and data yourself: Settings โ Security โ Delete account.
If a breach affects your personal data, we commit to notifying affected users and the relevant authority within 3ร24 hours, in line with Indonesia's Personal Data Protection Law (UU PDP 27/2022). Report a suspected security issue to [email protected].