Hosting model and location
The cloud provider, region, data location and data processing terms are defined contractually. The specific information depends on the production environment in use.
Security and privacy
GHSDoku separates tenants, roles and storage scopes technically. The infrastructure and data location used for the cloud service are defined in the applicable contract.
The cloud provider, region, data location and data processing terms are defined contractually. The specific information depends on the production environment in use.
Production instances are designed for HTTPS with secure cookies and HSTS. TLS termination is provided by the reverse proxy or ingress.
Platform role, customer membership, company roles and rights for sites, storage locations and work areas are checked separately.
Database and PDF storage are backed up separately. Operations documentation covers backup, restore, migration and rollback; operators must test recovery regularly.
Security-relevant and business actions are logged with context. Credentials, tokens and full payment data do not belong in application logs.
Data access is restricted to customer and company context. Shared substances are exposed only through explicitly configured relationships.
The application processes user, organisation and domain data for its functions. When billing is enabled, payment data is processed by Stripe and card details are not stored in GHSDoku.
Responsibility boundaries
GHSDoku is a tool for structured documentation. Correct classification, completeness, currency, risk assessment and compliance with operational or legal duties still require professional review. Certifications are mentioned only when they are demonstrably valid for the specific service.
Next step
Use your own sites and documents to assess whether GHSDoku fits your processes.