Each control on this page links to the documentation or the administration surface that implements it. Where the responsibility is yours rather than ours, it says that too.
OfficeDocs is a self-hosted document collaboration suite for real-time docs, writers, spreadsheets, presentations, forms and tables, with configurable AI agents built into every product, deployed into a private cloud you control.
Free plan
5 users
Team plan
$5 per user per month
Annual billing
20% off
Deployment
single-node or high-availability Kubernetes
Where the documents live
OfficeDocs runs inside your own Kubernetes cluster. Documents, metadata, permissions, version history and audit records are stored in your infrastructure, against your database and your object storage — there is no OfficeDocs tenancy holding a copy.
A single node is enough to evaluate the suite; production normally runs three or more control-plane nodes. Installation can run online, or from an offline image package on a network with no route to the internet.
Administration is a separate surface from the workspace. Tenants, users, licences, branding and AI configuration are managed in the operations platform, and those actions are recorded rather than being invisible.
The operation log is read-only by design: records cannot be created, edited or deleted from the product, including by an administrator. Each entry carries the event source, the operation type, the operating user, the object acted on and the timestamp.
AI is the part of a modern suite that usually means sending content to a vendor. Here the capabilities are endpoints you connect: a base model, an image model, embeddings, and optionally an online search service. Point them at a model inside your own boundary and the content stays there; point them at a provider you have approved and the data flow becomes a decision you made and can document.
Online search is a separate, optional service. Leaving it unconfigured disables that search connection; it does not prevent a configured model or embedding endpoint from receiving content. Review every enabled endpoint and validate its traffic against your egress policy.
One network fact worth designing around rather than discovering: browsers read and write document content directly against the object storage endpoint, so that endpoint has to be reachable from the client network. Plan the path deliberately instead of exposing it by accident.
Backups belong to the operator, and the runbook says which databases, buckets and configuration to capture — and which directories to leave alone. Define retention periods and legal-hold requirements with your records owner, then verify the required enforcement in your deployment. Self-hosting and backups alone do not establish a legal-hold control.
A private deployment splits responsibility, and a security review will ask which side each control sits on. The product ships the suite, the installer, the operations platform, the audit trail and the AI plumbing. Everything around it belongs to the operator:
Servers, storage and the Kubernetes cluster
Network policy: firewall, ports, load balancer and the object storage path
Middleware, when you bring your own MySQL, Dameng, Redis, MongoDB, Kafka or object storage
Backups, and a restore that has actually been rehearsed
Licence activation, and who holds administrator and operator accounts
Use these checks to turn the deployment boundary into evidence your reviewers can inspect.
Map document, database, object storage and AI endpoints, including the browser-to-storage path.
Test access with an administrator and a restricted user; verify the relevant operation log entries.
Exercise enabled AI services and compare observed connections with the approved endpoint list.
Restore a representative backup in a test environment and record the recovery result.
Assign owners for patching, account reviews, backups and retention; attach the test results to the security review.
The compliance questions teams ask
These are the long-form answers we publish: what a private deployment changes for each framework, and what an auditor will ask you to evidence. They are written for the person answering the questionnaire, not to claim a badge.
The deployment shape: single node, high availability, or air-gapped
Which middleware you run yourself, and which the installer provides
The object storage endpoint, and the network path browsers take to it
Whether AI capabilities are enabled, and exactly which endpoints they point at
Backup schedule, retention period, and who holds the restore procedure
Who holds administrator and operator accounts, and how that is reviewed
Frequently asked questions
Can an administrator edit or delete the audit log?
No. The operation log is read-only in the product: records cannot be created, modified or deleted from it, and each entry carries the event source, operation type, operating user, the object acted on and the timestamp. That is what makes it usable as evidence rather than as a convenience feature.
Does OfficeDocs send document content to an AI provider?
AI services use the endpoints you configure: a base model, an image model, embeddings and optional online search. Hosted endpoints may receive document context. To keep processing inside your network, use internal endpoints for every enabled capability and verify their traffic. Leaving online search unconfigured disables that connection, but does not block external model or embedding calls.
Where is OfficeDocs data stored?
In your own infrastructure: the suite runs in your Kubernetes cluster and writes to your database and your S3-compatible object storage. There is no OfficeDocs tenancy holding documents, metadata, permissions or audit records.
Do you publish certification status on this page?
No, deliberately. Certification is a fact about a company and a defined scope, not something a product page should improvise. Ask the team for the current status and the evidence pack your review requires; what is documented here is the control itself, and where you can check it.