Security and data control

Security you can
describe to an auditor.

Each control on this page links to the documentation or the administration surface that implements it. Where the responsibility is yours rather than ours, it says that too.

Last updated

OfficeDocs in numbers

OfficeDocs is a self-hosted document collaboration suite for real-time docs, writers, spreadsheets, presentations, forms and tables, with configurable AI agents built into every product, deployed into a private cloud you control.

Free plan
5 users
Team plan
$5 per user per month
Annual billing
20% off
Deployment
single-node or high-availability Kubernetes

Where the documents live

OfficeDocs runs inside your own Kubernetes cluster. Documents, metadata, permissions, version history and audit records are stored in your infrastructure, against your database and your object storage — there is no OfficeDocs tenancy holding a copy.

A single node is enough to evaluate the suite; production normally runs three or more control-plane nodes. Installation can run online, or from an offline image package on a network with no route to the internet.

Who can reach it

Administration is a separate surface from the workspace. Tenants, users, licences, branding and AI configuration are managed in the operations platform, and those actions are recorded rather than being invisible.

The operation log is read-only by design: records cannot be created, edited or deleted from the product, including by an administrator. Each entry carries the event source, the operation type, the operating user, the object acted on and the timestamp.

What leaves your network

AI is the part of a modern suite that usually means sending content to a vendor. Here the capabilities are endpoints you connect: a base model, an image model, embeddings, and optionally an online search service. Point them at a model inside your own boundary and the content stays there; point them at a provider you have approved and the data flow becomes a decision you made and can document.

Online search is a separate, optional service. Leaving it unconfigured disables that search connection; it does not prevent a configured model or embedding endpoint from receiving content. Review every enabled endpoint and validate its traffic against your egress policy.

One network fact worth designing around rather than discovering: browsers read and write document content directly against the object storage endpoint, so that endpoint has to be reachable from the client network. Plan the path deliberately instead of exposing it by accident.

Backups, retention and legal hold

Backups belong to the operator, and the runbook says which databases, buckets and configuration to capture — and which directories to leave alone. Define retention periods and legal-hold requirements with your records owner, then verify the required enforcement in your deployment. Self-hosting and backups alone do not establish a legal-hold control.

Who owns which control

A private deployment splits responsibility, and a security review will ask which side each control sits on. The product ships the suite, the installer, the operations platform, the audit trail and the AI plumbing. Everything around it belongs to the operator:

  • Servers, storage and the Kubernetes cluster
  • Network policy: firewall, ports, load balancer and the object storage path
  • Middleware, when you bring your own MySQL, Dameng, Redis, MongoDB, Kafka or object storage
  • Backups, and a restore that has actually been rehearsed
  • Licence activation, and who holds administrator and operator accounts

Run a security acceptance review

Use these checks to turn the deployment boundary into evidence your reviewers can inspect.

  1. Map document, database, object storage and AI endpoints, including the browser-to-storage path.
  2. Test access with an administrator and a restricted user; verify the relevant operation log entries.
  3. Exercise enabled AI services and compare observed connections with the approved endpoint list.
  4. Restore a representative backup in a test environment and record the recovery result.
  5. Assign owners for patching, account reviews, backups and retention; attach the test results to the security review.

The compliance questions teams ask

These are the long-form answers we publish: what a private deployment changes for each framework, and what an auditor will ask you to evidence. They are written for the person answering the questionnaire, not to claim a badge.

What a security review will ask for

  • The deployment shape: single node, high availability, or air-gapped
  • Which middleware you run yourself, and which the installer provides
  • The object storage endpoint, and the network path browsers take to it
  • Whether AI capabilities are enabled, and exactly which endpoints they point at
  • Backup schedule, retention period, and who holds the restore procedure
  • Who holds administrator and operator accounts, and how that is reviewed

Frequently asked questions

Can an administrator edit or delete the audit log?

No. The operation log is read-only in the product: records cannot be created, modified or deleted from it, and each entry carries the event source, operation type, operating user, the object acted on and the timestamp. That is what makes it usable as evidence rather than as a convenience feature.

Does OfficeDocs send document content to an AI provider?

AI services use the endpoints you configure: a base model, an image model, embeddings and optional online search. Hosted endpoints may receive document context. To keep processing inside your network, use internal endpoints for every enabled capability and verify their traffic. Leaving online search unconfigured disables that connection, but does not block external model or embedding calls.

Where is OfficeDocs data stored?

In your own infrastructure: the suite runs in your Kubernetes cluster and writes to your database and your S3-compatible object storage. There is no OfficeDocs tenancy holding documents, metadata, permissions or audit records.

Do you publish certification status on this page?

No, deliberately. Certification is a fact about a company and a defined scope, not something a product page should improvise. Ask the team for the current status and the evidence pack your review requires; what is documented here is the control itself, and where you can check it.