Papermark is committed to the security and privacy of our customers' data. We provide industry-leading security features to protect your sensitive documents and ensure compliance with global data protection regulations.
Last updated: October 29, 2025
Your documents are stored with enterprise-grade infrastructure, ensuring high availability and security at all times.
Out of the box, Papermark is hosted in Europe by default.
GDPR-compliant hosting in eu-central-1 (Frankfurt) for European customers requiring data residency.
Hosted on AWS infrastructure in us-east-1 (N. Virginia) with automatic backups and disaster recovery.
Choose your preferred hosting region via Enterprise plan
Access to 38+ data centers worldwide for optimal performance and compliance
Automatic compliance with GDPR, CCPA, and local regulations
Full control over where your sensitive documents are stored
Papermark provides industry-standard encryption to protect your sensitive documents at every stage.
All documents stored on our servers are encrypted using AES-256 encryption, the same standard used by banks and government institutions.
All data transmitted between your browser and our servers is encrypted using TLS 1.2, protecting against interception and tampering.
Automatic key rotation and secure storage of encryption keys
Advanced controls to prevent unauthorized data extraction
Network isolation with strict access controls and monitoring
End-to-end encryption ensures only you can access your data
Papermark is available as SaaS and open source, meaning our code is publicly reviewable by the community and security researchers. Open development leads to transparent security practices, faster vulnerability discovery, and rapid patching.
Independent audits and peer review reduce hidden risks and improve overall security posture.
Clear dependencies, public change history, and reproducible builds enhance trust and compliance.
Control exactly who can access your documents and what they can do with them.
Granular access at file and folder level, with inherited permissions for consistency.
Restrict access by domain, email, or IP with organization-wide allow/deny lists.
Maintain version history and control which version is visible to viewers.
Apply custom watermarks with viewer email or name to prevent unauthorized sharing.
Allow viewing only or enable downloads based on your requirements.
Require NDA acceptance prior to access with auditable records.
Require a password to access documents for an extra security layer
Share documents on-brand with custom themes and logos
Restrict access to specific email addresses or domains only
Block screenshots and screen recordings on supported browsers
Manage team access and permissions across all documents
Folder-level permissions cascade to all documents within
Track every interaction with your documents for complete visibility and compliance.
Get instant notifications when someone views your documents, including who accessed it and when.
See exactly which pages were viewed, for how long, and how many times each page was accessed.
Capture viewer details including email, location, device, and browser information.
Complete record of who accessed which documents and when
Monitor all document downloads with timestamp and user details
Export audit logs for compliance and reporting purposes
Automated daily backups with point-in-time recovery to protect against data loss.
Built-in protection against distributed denial-of-service attacks for high availability.
Enterprise single sign-on support with SAML for seamless and secure authentication.
Open-source and available for self-hosting for maximum control over your data.
Enterprise SLA guarantees with redundant infrastructure
Global CDN ensures fast document delivery worldwide
Full API access for custom integrations and automation
Dedicated support team with guaranteed response times
We are committed to meeting the highest standards of data protection and privacy regulations.
Papermark has achieved SOC 2 Type II certification, demonstrating our commitment to the highest standards of security, availability, and confidentiality.
Our SOC 2 Type II report is issued by an independent third-party auditor, validating our security controls over an extended period.
We meet all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Comprehensive security policies and procedures to protect customer data
Strict access controls and authentication mechanisms
Controlled processes for system changes and updates
Documented procedures for detecting and responding to security incidents
If you are a resident of the EU/EEA, you have certain rights under the GDPR. We take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. Learn more at EUR-Lex.
Request access to, update, or deletion of the information we hold about you.
Correct inaccurate or incomplete personal information.
Object to processing or request restriction of processing in certain cases.
Receive a copy of your data in a structured, machine-readable format.
Withdraw consent at any time where processing relies on consent.
To exercise your rights or request removal of your data, email support@papermark.io.
CalOPPA requires commercial websites to post a privacy policy and disclose how personal information is collected and shared. Learn more at ConsumerCal.
Users can visit our site anonymously.
Our Privacy Policy link includes the word "Privacy" and is easy to find.
Users will be notified of privacy policy changes on our Privacy Policy page.
Users can update personal information by emailing support@papermark.com.
California residents are entitled to learn what data we collect, request deletion, and opt out of sale (sharing). Learn more at the California Legislative Information website.
Request the categories, sources, business purpose, third parties, and specific pieces of personal information we hold.
Request deletion of personal information we hold about you, subject to applicable exceptions.
We do not sell or rent your personal information to any third parties.
To exercise your CCPA rights, email support@papermark.io.
Review our Subprocessors and Terms of Service.