FAQ
Frequently asked questions
What do people ask about docivault before signing up?
About the product
What docivault is, and what is actually built today
What is docivault?
docivault is a secure workspace for exchanging documents with people outside your own team — clients, patients, applicants, families, counterparties, anyone. You get a private workspace, you add the people you exchange with as contacts, and documents move between you in one place instead of across email, WhatsApp and a shared drive.
Which parts of docivault are actually built today?
Most of the core. Accounts and sign-in, passkeys, two-factor authentication, workspaces, roles and access scoping, contacts, team members, categories, settings and idle sign-out are all built and running — and so are documents and the three spaces, upload, in-browser preview of common formats, comments and reactions, sharing by expiring link, the activity feed and an admin analytics dashboard. Document requests are in progress. Not built: bulk import from Drive or OneDrive, WhatsApp and Slack connectors, billing, a public API, an AI assistant, e-signature, and one complete record of every view and download. The roadmap page lists every feature with its real status.
What are the three spaces?
Every contact gets three independent document spaces. Private is you and your admins only. Shared is your assigned team. Client is what the contact themselves can see. A document moves between them when you decide it is ready, so a draft cannot become the thing they see by accident. This is built and available now — you upload into a space and move a document between spaces as a deliberate action rather than a permissions change.
Can I move documents in from Google Drive or my inbox?
Not yet. Import from Google Drive, OneDrive and email is on the next-up list. Today you upload from your device.
Does docivault read my documents with AI?
No. There is no AI feature in the product today, so nothing is being read, summarised or used for training. Preview converts Word and Excel files to something viewable inside your own browser, not on a server, and no third party sees the contents. An AI assistant is on the roadmap; when it ships it will be explicit about what it touches and it will be possible to not use it.
Who builds docivault?
It is built by Rounak Maheshwari, self-funded and without outside investment. That is the reason this site is unusually specific about what is finished — a small product cannot afford a reputation for overpromising.
Pricing
What it costs, and who pays for it
How much does docivault cost?
Free, $19, $49 or $149 a month for the whole workspace, billed flat rather than per seat. Annual billing is 2 months free. The external contacts you exchange documents with are unlimited on every paid plan and are never billed — you pay for your own team’s seats, not for the people you serve.
Do the people I exchange documents with have to pay?
No, and there is no limit on how many of them you have. They are contacts, not seats. This is the main way docivault differs from tools priced per user or per client: adding the two hundredth person you exchange documents with costs the same as adding the second.
Do I need a credit card to start?
No. Billing is not built yet, so there is nothing to enter and nothing to cancel. The Free plan has no expiry.
What happens if I stop paying?
Billing is not built yet, so today nothing happens because nothing is charged. When it ships, a lapsed workspace drops to the Free plan’s limits rather than being deleted, and you keep read access to your documents.
Security and data
Certification, data location, and how a document is protected
Is docivault ISO 27001 or SOC 2 certified?
No. We hold no ISO 27001 certificate and no SOC 2 report, and no audit has been undertaken. Both are on the roadmap with no date promised. Anyone who needs a certificate today should not choose docivault yet, and we would rather say so than find out later.
Where is docivault data stored?
In India. The database runs in Supabase’s ap-south-1 region in Mumbai, files are stored in Cloudflare R2, and the application is served from Vercel’s network with functions in US East. Data is not stored in the EU today. EU data residency is on the roadmap — it is a migration rather than a setting, so we will not claim it before it is done. The subprocessors page lists every vendor and its region.
How is a document actually protected?
Files live in private object storage that has no public URL. Access is granted by short-lived signed links generated per request, so a link that leaks stops working. Postgres row-level security policies decide who can read a row, enforced in the database rather than in application code. Encryption is applied in transit and at rest. Sign-in supports passkeys and authenticator-app two-factor, and idle sessions sign themselves out. The security page explains each of these rather than listing badges.
Can documents be shared by a public link?
Yes, if you choose to. A share link can either be open to anyone holding it or restricted to email addresses you name, and either way it expires — you pick the window when you create it, from an hour to thirty days, and you can revoke it earlier. An open link trades access control for convenience, so the restricted mode is the better default for anything sensitive. Everything inside the workspace itself stays behind sign-in and role-based access.
Can I get my data out?
One document at a time, yes — you can download anything you can see. What does not exist is a bulk export: no "download my whole workspace" button and no audit-trail export. What you can also do today is delete — your account, or an entire workspace, self-service from settings, with no need to ask us. Deletion is not portability, and answering this with a flat "yes" would be the wrong word.
Still deciding? The fastest way to find out is to try it
Sign up and see the workspace for yourself — nothing here is a substitute for using it.
- No credit card
- Free plan, no expiry
- The people you exchange with are free