Skip to content

A critical document system should not ask for blind trust.

Dokus sits between an approved source, application data, and the copy someone receives. Before you put it there, you should know what it records, what you can take out, and what the public alpha does not promise.

  • Recorded origin
  • Controlled downloads
  • Exportable audit
  • Stated limits

Start with the evidence behind one output.

A successful render is not enough. Dokus keeps the origin needed to explain the result after the request is over.

The exact document

A run identifies the document version, package fingerprint, and source hash selected when it was accepted.

The exact behavior

The saved blueprint revision or inline blueprint digest and the compiled render plan stay with the run.

The exact request

The accepted input digest and requested outputs remain part of the run record instead of disappearing after rendering.

The exact result

Completed outputs include their own digest and the compiler, engine, and font identities used to create them.

Access is deliberate. Evidence can leave with you.

Reading a run never creates a public download link. Your server explicitly issues a short-lived output link and can revoke it. Completed outputs include a digest. Tenant audit events can be exported as a digest-checked NDJSON file.

Finished documents

Download access is finite, policy-bounded, revision-owned, and audited. A link is issued for a specific output instead of appearing on every read.

Audit evidence

Query tenant events in the API or request an immutable-watermark export whose downloaded bytes can be checked against its hash.

Data has a lifecycle. Each part of it has a surface.

Retention, holds, erasure, and offboarding are implemented, but they do not all live in the same place. Read this before assuming a self-service control exists.

In your tenant API

Controls your server can call today

  • A retention policy with separate periods for inputs, outputs, and evidence, read and updated per tenant.
  • Legal holds placed on a run or a document, and released later.
  • Erasure requests for the customer data behind a run.
  • Retirement of a document that should no longer be used.
Operator control plane

Actions Dokus performs for you

  • Tenant offboarding runs on a separate operator server with its own credentials. It is not a self-service button.
  • Customer-data purges after offboarding are internal jobs whose effect is recorded on every affected row.
Not promised

Commitments that do not exist yet

  • Data residency or region selection.
  • Backup and restore objectives.
  • A complete account-portability guarantee.

The public alpha has boundaries.

These are not footnotes. They are the limits you should use when deciding where Dokus belongs today.

Production terms

Dokus is a public alpha. A production SLA, support policy, and stable production licence are not available yet.

Pricing

There is no public price or paid plan today. We will publish pricing only after the product can support a real, measurable model.

Document compatibility

Support is tested feature by feature. Dokus does not promise that every Microsoft Word feature will render, so evaluation should include your real documents.

Data location

No public data-residency commitment has been published. Do not assume a region or regulatory boundary that Dokus has not stated.

Account exit

Finished outputs and audit evidence can be exported today. A complete account-portability guarantee has not been published.

Browser editing

The current WASM component displays and selects documents. Editing and saving are planned for a separate package and are not available now.

Test the claim with a document your product actually depends on.

The alpha is useful for evaluation. It should earn a larger role with evidence, not promises.