DocStash

Security

Last updated: 30 September 2026

How DocStash protects your documents and your data, from where files are stored to who can see them and how every action is recorded.

How we protect your documents

Encryption in transit

All data is encrypted in transit with TLS.

Encryption at rest

Data is encrypted at rest, and so are your stored credentials.

Authentication and sessions

You sign in with Google or your own SSO, so we never see your password. Agent access uses OAuth 2.1 tokens scoped to you and revocable at any time.

Sandboxed execution

Live apps run in a browser sandbox isolated per document, so one app can never reach another's data or your session.

Least privilege storage

Storage credentials are never exposed to clients, and each file is served through a temporary link scoped to that one file.

Access control

Private by default

Documents are private to you and scoped to your organization. A document is public only when you explicitly publish it.

Checked on every request

Access is verified against membership or an explicit grant on every request, so removing someone ends their access immediately.

Enterprise SSO

Sign in through your own identity provider over standard OIDC. Employees on your domain route to your IdP at sign in. Remove them there and access ends here.

Audit and monitoring

Audit trail

A permanent record of every action, showing who did what and when.

No content in logs

Logs record actions and metadata, never your document contents.

Access logs

Views are recorded when someone is signed in, not just edits, so you can see who opened a document and not only who changed it.

Exports on request

Your complete audit history is available to your security team on request.

Data protection

You control your data

You own the documents you create and can delete them at any time. Account deletion and a full data export are available too.

Your storage

Bring your own S3 bucket, or any S3 compatible storage (Cloudflare R2, Backblaze B2, MinIO, GCS). File bytes land in your storage.

AI governance

We never train on your content

Your documents are never used to train AI models.

Agents act only as you

A connected agent works on your own account, and we receive only the specific tool inputs it sends, never your conversation with it.

Reliability

Managed infrastructure

DocStash runs on managed cloud infrastructure (Google Cloud, Supabase, and Vercel's edge), with redundancy and backups at the provider level.

Subprocessors

The infrastructure providers we rely on are listed in our Privacy Policy.

MCP server security

DocStash is a remote MCP server (Streamable HTTP over HTTPS) that lets your AI assistant create, save, and share documents in your DocStash account. This section describes exactly how it authenticates, what its tools can do, and how your data is handled.

Endpoint:https://mcp.docstash.ai

Authentication

Connections use the MCP OAuth 2.1 flow, including server metadata discovery (RFC 8414) and Dynamic Client Registration (RFC 7591). You sign in through your MCP client in your browser, and the resulting token is scoped to the DocStash account you authorize.

What the tools can do

The server exposes a fixed, published set of tools. The live schema is discoverable by any client via the standard MCP tools/list handshake at the endpoint above.

The full contract (every tool description, input schema, the standing server instructions, and what each tool returns) is mirrored publicly at github.com/docstash/mcp-contract.

Create

Author a new document of the given type.

create_pagecreate_appcreate_pdfcreate_docxcreate_sheetcreate_text

Edit

Modify the contents of an existing document of the given type.

edit_pageedit_appedit_pdfedit_docxedit_sheetedit_text

Render

Render an existing document and show it to you as a live preview. The content is not read into the assistant.

show_pageshow_pdfshow_docxshow_sheetshow_text

Read

Read a document's content into the assistant's context, and list your documents.

read_documentlist_documents

Screenshot

Render a screenshot image of one of your documents.

screenshot_document

Save & manage

Save a preview as a document, trash or restore it, and control who it is shared with.

stashdiscardmanage_documentmanage_sharing

Account

Read your organizations and members, and switch the active organization.

get_organizationsset_organizationlist_org_members

For how we collect, use, and delete data, see our Privacy Policy and Terms.