Vukorix is operated by Osmicro Networks Pty Ltd, an Australian company registered in New South Wales, and personal information is handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Some sub-processors work offshore, and sending them data is a cross-border disclosure under Australian Privacy Principle 8. Each sub-processor is named, with its purpose and location, in the Privacy Policy.
The rest of this page is a technical overview for security, risk, and procurement teams: trust boundaries, encryption, access control, product processing, monitoring, and recovery.
Last reviewed: 24 June 2026
Vukorix separates the client and recipient experience, product processing, stored data, and service operations into distinct security responsibilities. Requests reach the application through the Cloudflare edge described below.
Users authenticate to their organisation account. Recipients use controlled links and any required PIN, password, SMS code, expiry, or view limit. Private mode encryption begins in the sender's browser for supported file transfers. Cloudflare fronts the Vukorix domains for DNS and edge protection; your documents are stored in Sydney.
Vukorix applies account access rules, recipient controls, product processing, status updates, and relevant event recording. Standard-processing features can access file contents only where the selected product requires it.
Stored content is encrypted and held in the Sydney (SYD1) region, alongside the production application and database. Operational access is restricted, monitoring and alerts run continuously, and backups and recovery procedures are maintained.
The security model differs according to the product feature being used. Features that need document preparation, previews, signing, forms, or messaging require secure server processing. Supported Private mode transfers keep file contents outside the Vukorix processing boundary.
Standard secure processing supports product features that need access to document contents. Private mode moves supported file encryption into the sender's browser.
Scroll sideways to compare security paths.
| Area | Standard secure processing | Private mode |
|---|---|---|
| Where encryption begins | The connection between the browser and Vukorix is encrypted. | The file is encrypted in the sender's browser before upload. |
| Stored content | Stored file content is protected using AES-256-GCM with a Vukorix-managed key. | Vukorix stores encrypted file data and does not have access to the file contents. |
| Content processing | Authorised Vukorix systems can process document contents where required by the selected product feature. | Vukorix systems do not decrypt the supported file contents. |
| Feature support | E-Sign, Smart Forms, Document Library, previews, redaction, and Secure Exchange messaging. | Secure Share, Secure Receive, and supported Secure Exchange file transfers. |
| Recovery | Content remains available through the organisation's authenticated account while retained by the service. | The file unlocks with the share link, passphrase or recipient account that holds its key. |
| Metadata | Account, recipient, product, and event information may be recorded according to the selected feature. | File contents stay encrypted, and event information is recorded to operate and secure the service. |
To operate and secure the service, Private mode events can record the sender identity, timestamps, file size, and ciphertext integrity information.
Recipient IP address and user-agent information are not retained on Private mode events.
Filenames can be hidden where the selected product supports that option.
The file unlocks with the share link, passphrase or recipient account that holds its key, so keep the link and passphrase safe.
Scroll sideways to see every column.
| Product | Processing path | Why content processing is needed | Security result |
|---|---|---|---|
| E-Sign | Standard secure processing | Prepare the PDF, place fields, complete signing, and produce the signed document and records. | Encrypted transfer and storage, optional recipient access checks, signed PDF and audit certificate. |
| Document Library | Standard secure processing | Store approved PDF templates and create fresh E-Sign drafts. | Encrypted transfer and storage with authenticated organisation access. |
| Smart Forms | Standard secure processing | Prepare the PDF, suggest and place fields, and produce the completed PDF. | Encrypted transfer and storage, with the completed PDF kept with the related request or exchange. |
| Secure Share | Standard secure processing or Private mode | Create controlled links with expiry, view limits, and optional access checks. | Private mode adds browser-side encryption and prevents Vukorix from accessing supported file contents. |
| Secure Receive | Standard secure processing or Private mode | Collect requested client documents and show request status. | Private mode adds browser-side encryption for supported client uploads. |
| Secure Exchange | Standard secure processing and Private mode for supported file transfers | Connect incoming files, outgoing documents, messages, Smart Forms, and E-Sign items. | Messages, Smart Forms, and E-Sign items use Standard processing, and Private mode covers supported file transfers. |
Vukorix records relevant account and product events and provides product-specific completion records.
Completed E-Sign documents include the signed PDF and an audit certificate.
Completed Secure Exchange items can include an audit certificate.
Manual PDF redaction is available inside the E-Sign and Smart Forms editors. The selected page is rasterised, opaque areas are applied, and the exported page is produced as an image-based copy.
The underlying PDF text is removed from the selected area in the exported copy. The document owner retains the original source document.
The providers that host the service maintain recognised information-security certifications, such as ISO 27001.
Automated monitoring and alerts run around the clock to help identify and investigate operational issues.
Backups and recovery procedures are maintained as part of normal service operations.
Changes are tested before release, with security and reliability reviewed as the service evolves.
When monitoring identifies an issue, Vukorix investigates it, uses available recovery procedures where needed, and applies what is learned to improve the service.
Administrative access is limited to authorised purposes and is not exposed through the public customer experience.
Customer Content is handled according to the selected product and encryption path. Standard-processing features can access file contents where required. Private mode protects supported file contents from Vukorix access.
Vukorix retains the account, product, event, and technical information required to operate, secure, and support the service. That metadata is held in the same region as the documents it relates to. Aggregated website analytics data and operational email delivery records sit with the overseas sub-processors described below.
Retention and deletion are governed by the published Privacy Policy and the controls available in the selected product. The Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) applies to eligible data breaches.
Your documents and account data are stored in Sydney. Some sub-processors work offshore, including Google Analytics for aggregated website analytics and the transactional email provider that delivers operational email. Those are disclosures to overseas recipients under Australian Privacy Principle 8, and every sub-processor is listed with its purpose and location in the Privacy Policy.
Security and privacy are considered when product behaviour and data handling are designed.
Changes are tested before release, with security and reliability included in the review.
Vukorix reviews technical changes, customer feedback, operational events, and recognised security practices to improve the service.
Vukorix reviews its security design and operations against recognised security and privacy guidance, including the Australian Privacy Principles.
Security here is built on controls you can check: encryption in transit and at rest, a documented split between Standard encryption and Private mode, restricted operational access, audit logging on every action, monitoring, and tested backups. The sections above set each of those out in detail.
The providers that host the service maintain recognised information-security certifications, such as ISO 27001.
Running a vendor security assessment? Email security@vukorix.com with what your process needs and we will answer it directly.
The Vukorix production application, its database, and uploaded files all run in the DigitalOcean Sydney (SYD1) region. Cloudflare fronts the Vukorix domains for DNS and edge protection. Some sub-processors process data overseas, including Google Analytics for aggregated website analytics and the transactional email provider that delivers operational email. Those are cross-border disclosures under Australian Privacy Principle 8, and every sub-processor is listed with its purpose and location in the Privacy Policy.
Vukorix is operated by Osmicro Networks Pty Ltd, an Australian company registered in New South Wales. Personal information is handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the Notifiable Data Breaches scheme applies, and complaints can be taken to the Office of the Australian Information Commissioner.
Files are encrypted during transfer and while stored. Standard secure processing uses AES-256-GCM for stored file content, with a Vukorix-managed key. Private mode adds browser-side encryption for supported file transfers.
E-Sign, Smart Forms, Document Library, previews, blackout and redaction, and Secure Exchange messaging require secure server processing. Private mode prevents Vukorix from accessing supported file contents.
Vukorix accounts use two-factor authentication, including WebAuthn passkeys and authenticator apps.
Automated monitoring and alerts run around the clock. Backups and recovery procedures are maintained, and changes are tested before release.
The providers that host the service maintain recognised information-security certifications, such as ISO 27001. Our own controls are set out in detail on this page: encryption in transit and at rest, the split between Standard encryption and Private mode, restricted operational access, audit logging, monitoring and tested backups. If your assessment needs more detail in writing, email security@vukorix.com and we will answer it directly.
Review the published policies, or put your questions to the Australian team that operates Vukorix.