> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> How credentials, transmission and your data are protected – and what you control yourself.

## Sign-in and roles

Signing in to Docusnap365 requires **multi-factor authentication**. It is
mandatory for all users.

What a user can see and change is set by their role; rights can be further
restricted per module. See [Users and Roles](/docs/en/settings/users).

## Encryption

* **Transmission:** every connection — browser, gateway, AI assistant — is
  encrypted.
* **Storage:** databases and data stores are held encrypted.
* **Vault:** credentials for scans are encrypted in the browser before they
  are transmitted. The gateway receives them only for the duration of a job.
  Credentials with storage location *Gateway* never leave the gateway.

## The gateway

The gateway connects outbound to Docusnap365; there are no inbound
connections. It **reads** your systems and changes nothing on them. It only
runs jobs created within your tenant.

Scan results are encrypted on the gateway before they are transmitted. Every
transfer to the data store uses a **time-limited access key** valid only for
that transfer.

*Support Mode* on the gateway, which lets Docusnap support see the gateway,
is a switch that only you set. See [Managing Gateways](/docs/en/scan/gateway).

## Tenant separation

Every customer has their own database. Transfer storage and storage are
strictly separated per tenant. A gateway belongs to exactly one tenant.

## AI assistant

The AI assistant's language models are **operated in Europe**; processing is
covered by a data processing agreement. Your questions and the data read to
answer them are not processed outside Europe. The assistant acts with the
rights of the signed-in user. See
[Permissions and Data](/docs/en/assistant/permissions-and-data).

## Support access

Docusnap support has no access to your tenant. For assistance, you grant
access explicitly — time-limited and revocable at any time. See
[Support](/docs/en/settings/support-access).

## Location, backup, deletion

* **Location:** Microsoft Azure, West Europe region. Data does not leave the
  region.
* **Backup:** your database is backed up continuously. The period for which a
  restore is possible depends on the edition: 7, 14 or 30 days.
* **Deletion:** after the contract or trial ends, your data is retained for
  **30 days**. It is then deleted. You are notified before deletion.

## Certification

Docusnap GmbH is certified to **ISO 27001**. Microsoft Azure's data centers
are certified to ISO 27001, ISO 27017 and ISO 27018, among others.

## Next steps

[Architecture](/docs/en/getting-started/architecture) describes how Docusnap365 is
built. To set up the gateway:
[Scanning Your Network](/docs/en/getting-started/inventory).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.