DocinVault achieves ISO/IEC 27001:2022 certification

DocinVault has achieved ISO/IEC 27001:2022 certification. Learn what the certification means for our information security management system and for hospitality operators using DocinVault to handle guest identity workflows.

DocinVault ISO/IEC 27001:2022 information security certification announcement

Information security has been a core part of DocinVault from the beginning.

Today, we are pleased to announce that DocinVault has achieved ISO/IEC 27001:2022 certification for its information security management system.

The certification follows an independent assessment of the policies, processes, controls, and responsibilities used to manage information security across the certified scope of our operations.

For a company working with guest identity verification, this milestone carries particular importance. Hospitality operators trust DocinVault to support workflows involving sensitive identity information. That trust must be supported by documented controls, clear accountability, ongoing risk management, and independent review.

01

What is ISO/IEC 27001?

ISO/IEC 27001 is an international standard for information security management systems, commonly referred to as an ISMS.

Rather than focusing on a single security tool, the standard examines how an organization manages information security as a complete and continuing process.

This includes areas such as:

  • Information security risk assessment
  • Access control
  • Employee responsibilities
  • Supplier and third-party management
  • Incident response
  • Business continuity
  • Secure development practices
  • Asset management
  • Data retention and disposal
  • Monitoring and internal review
  • Continual improvement

Certification confirms that DocinVault has established an information security management system that was independently assessed against the requirements of the standard within its defined certification scope.

It does not mean that security risks disappear. No responsible organization should make that claim. It means that DocinVault has a structured, audited, and continuously maintained system for identifying, managing, and reducing information security risks.

02

Why this matters for travel and hospitality

Guest identity workflows often involve some of the most sensitive information handled by hospitality teams.

Passports and identity documents may contain:

  • Full legal names
  • Dates of birth
  • Document numbers
  • Nationality information
  • Photographs
  • Signatures
  • Document expiry dates

Despite the sensitivity of this information, many operators still receive passport images through WhatsApp, email, OTA messaging, front-desk scanners, or paper copies.

These documents may then remain across employee phones, inboxes, shared folders, local computers, and property management system attachments.

DocinVault was created to replace that fragmented process with a controlled verification workflow.

Guests verify through a secure browser session. Operators receive the verification result and the structured fields configured for their workflow. Raw document access is restricted rather than being distributed through everyday communication tools.

Achieving ISO/IEC 27001 certification supports this product approach with a formal information security management framework.

03

What the certification means for DocinVault customers

For property managers, aparthotels, boutique residences, and booking platforms, the certification provides independent evidence that information security is managed through defined processes rather than informal promises.

A risk-based security program

DocinVault identifies and evaluates information security risks based on their potential effect on the company, its systems, its customers, and guest information.

Security priorities are reviewed according to risk, not selected only because a tool or control is currently popular.

Defined access responsibilities

Access to sensitive systems and information must be connected to a legitimate operational responsibility.

The certification process required DocinVault to formalize how access is approved, managed, reviewed, and removed.

Documented incident management

Security incidents require preparation before they occur.

DocinVault maintains defined responsibilities and procedures for identifying, reporting, assessing, responding to, and learning from security events.

Supplier and infrastructure oversight

Identity verification services depend on infrastructure, software, and specialist technology providers.

Our information security management system includes processes for evaluating relevant suppliers, understanding associated risks, and managing security responsibilities across those relationships.

Security throughout product development

Security is considered during product planning, development, testing, deployment, and maintenance.

For DocinVault, this supports the continued development of verification sessions, operator dashboards, API connections, retention controls, audit histories, and hospitality system integrations.

Continual review and improvement

ISO/IEC 27001 certification is not a one-time product badge.

The management system must continue to operate after the certification audit. Controls, risks, incidents, internal reviews, corrective actions, and improvement opportunities remain part of the ongoing process.

04

Supporting privacy through product design

Certification is one part of DocinVault's broader approach to identity data.

Our product is designed around practical privacy principles.

Reduce unnecessary document distribution

Raw identity documents should not be copied into staff messaging accounts, personal phones, email inboxes, and uncontrolled folders as part of the standard workflow.

Return only what the workflow requires

Operators receive verification status and configured structured information instead of unrestricted document copies by default.

The exact output can depend on the operator's workflow and applicable requirements.

Control access

Sensitive information should be available only to approved users who need it for a defined responsibility.

Maintain accountability

Verification events and relevant access activity can be recorded to provide a clearer operational history.

Apply defined retention

Identity information should not remain indefinitely simply because nobody remembered to delete it.

DocinVault supports defined retention and deletion processes based on the customer's workflow and applicable obligations.

05

What certification does not change

ISO/IEC 27001 certification does not replace the responsibility to configure and use DocinVault appropriately.

Customers must still determine:

  • Which identity information they are legally permitted or required to collect
  • The lawful basis for processing that information
  • Which employees require access
  • How long information must be retained
  • Which local reporting obligations apply
  • How DocinVault should be configured for their operating market

The certification also does not mean that every feature, integration, customer system, or third-party service is automatically covered without reference to the formal certification scope.

We believe transparency about these boundaries is part of responsible security communication.

06

A milestone built for long-term trust

DocinVault exists because guest identity information deserves a more controlled workflow than passport images sent through chats and stored across staff devices.

Achieving ISO/IEC 27001:2022 certification is an important confirmation of the systems and responsibilities we have built around that mission.

It gives our customers independent assurance that information security is managed as a continuing business discipline across the certified scope of DocinVault.

Our work does not stop with certification.

As DocinVault adds new hospitality workflows, integrations, customers, and operating markets, we will continue reviewing risks, strengthening controls, and improving the way sensitive identity information is handled.

Hospitality operators and booking platforms can contact our team to request further information about DocinVault's security program and certification scope.

07

Frequently asked questions

Clear answers about the certification, its scope, and what it means for hospitality identity workflows.

Discuss security and identity verification with our team

Learn how DocinVault can support a more controlled guest identity workflow across your properties or booking platform.

contact@docinvault.com