Encryption
AES-256-GCM encryption for documents at rest. TLS 1.3 in transit. Every upload is verified against a SHA-256 hash before it counts as accepted.
Security and trust
Business and financial records are sensitive. We treat them that way.
AES-256-GCM encryption for documents at rest. TLS 1.3 in transit. Every upload is verified against a SHA-256 hash before it counts as accepted.
Granular permissions per document, folder and workspace. Anonymous share links with an expiry date. A permanent append-only audit log that cannot be altered.
Data does not leave the European Union.
A retention guard blocks deletion of documents before the statutory period ends. Documented izlučivanje under Pravilnik 34/2022, with a written Zapisnik o izlučivanju. Weekly integrity verification of every document.
Dokumentar.rs encrypts data with AES-256-GCM and keeps every file on servers in the European Union. Each document gets a SHA-256 checksum on import. Once a week the system re-checks those checksums and warns you if anything does not match.
The audit log is append-only at database level: no entry can be altered or deleted before the prescribed period expires. Documented izlučivanje follows the official workflow with a Zapisnik o izlučivanju, under Pravilnik 34/2022.
We meet the requirements of Zakon o arhivskoj građi (6/2020), Zakon o računovodstvu, Zakon o zaštiti podataka o ličnosti (ZZPL/GDPR) and Pravilnik o obrascu arhivske knjige 34/2022. For B2B clients we offer a data processing agreement (DPA) on request.
For B2B clients who need a formal personal data processing agreement (DPA) under ZZPL/GDPR - send us a request through the contact form and we will supply the completed document for signature.
Request the DPAWe are glad to walk through the specific controls and to sign a DPA.