DocAccess
United States · docaccess.com · 9 vendors
Resilience scores
- Digital Sovereignty: 56
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Airalo — Telecommunications — Singapore
- Google LLC — Technology — United States
- Line Systems ApS — Other — Denmark
- and 6 more
Services catalogue
1 service in catalogue across 1 category; runs on 9 sub-vendors.
- DocAccess
Insights
Last updated 2026-08-14 · revision 2
9 direct vendors, 115 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 2
- Singapore: 1
- UK: 1
Subvendors by controlling owner country (sample)
- United States: 74
- France: 1
- Belgium: 2
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
DocAccess exhibits a medium level of migration readiness. The company benefits from a cloud-aware tech stack, leveraging AWS services, CDNs, and various APIs (Google Translate, Google Drive, Aira), which suggests a foundation amenable to cloud migration. The SaaS nature of their platform and the availability of a REST API for programmatic integration indicate a modern, modular approach. The geographic diversity of their vendor HQs (Singapore, United States, Denmark) is also a positive factor, potentially simplifying vendor-related aspects of migration compared to a highly concentrated vendor base. However, several factors reduce their overall readiness. There is no explicit mention of advanced cloud-native practices such as containerization (Docker, Kubernetes) or a microservices architecture, which are strong indicators of high migration readiness. The most significant challenge is the complete lack of financial data (revenue concentration, growth history), making it impossible to assess their capacity to fund a potentially complex migration. Furthermore, while vendor geographic diversity is present, the 'Vendor Lock-in Risk' is unknown, and the exact number of unique vendors for the 8 listed services is unclear, which could lead to unforeseen complexities during migration. Finally, the company's strong focus on meeting stringent compliance requirements (ADA, Section 508, DOJ Title II, WCAG 2.1 AA) for its products could translate into complex regulatory and compliance hurdles for its own system migrations, requiring careful planning and validation in new environments. Data residency requirements are not specified, which is a neutral point.
Compliance
10 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
DocAccess is a US-based SaaS platform (hosted on AWS US regions only) primarily serving US public-sector organizations. GDPR applicability is limited but acknowledged: the Privacy Policy explicitly addresses GDPR and states that for any personal data of EU/EEA or UK individuals contained in customer content, DocAccess acts as a data processor on the customer's documented instructions. The company does not sell personal data, minimizes data collection, encrypts data at rest (AES-256) and in transit (TLS 1.2+), and has defined data retention and deletion schedules. Risk is Low because: (1) EU/EEA data exposure is incidental and limited (EU residents may appear in customer-uploaded documents), (2) DocAccess acts as a processor rather than a controller, (3) the company has publicly acknowledged GDPR obligations, (4) enforcement risk against a US-based processor with minimal EU footprint is lower than for EU-established controllers. However, the absence of a named Data Protection Officer (DPO), no explicit mention of Standard Contractual Clauses (SCCs) for international transfers, and no formal GDPR audit create residual partial compliance gaps.
Evidence: https://docaccess.com/privacy-policy, https://docaccess.com/security-practices, https://docaccess.com/terms-of-service
ISO 27001 (source) — Assessment Required
DocAccess explicitly states it does not hold ISO 27001 certification, but its security program 'aligns with ISO 27001 control families.' This means the company has implemented many ISO 27001-aligned controls without undergoing formal third-party certification. For a SaaS platform serving government entities, ISO 27001 certification is increasingly expected but not universally mandated. Risk is Low because: (1) the company has a documented, mature security program aligned with ISO 27001, (2) SOC 2 Type I has been achieved (overlapping control coverage), (3) the absence of formal certification is a gap in assurance rather than a gap in security controls, and (4) the primary customer base (US local governments) does not universally require ISO 27001 certification.
Evidence: https://docaccess.com/security-practices, https://docaccess.com/privacy-policy
FERPA — Compliant
DocAccess explicitly addresses FERPA in its Privacy Policy (Section 14). The company serves school districts and educational institutions and has structured its data processing to comply with FERPA requirements: it acts as a service provider at the institution's direction, does not use student education records for any other purpose, and the institution retains full ownership and control. Document readers (including students) are anonymous. Risk is Low because: (1) FERPA compliance is explicitly addressed, (2) the company acts as a service provider (not a school official with independent access), (3) no student personal data is collected from document readers, and (4) the company's role is limited to processing publicly published documents.
Evidence: https://docaccess.com/privacy-policy
Financials
Three-year financials
- null:
- null:
- null:
Financial Resilience Score: 6/10
CivicPlus (parent of DocAccess) demonstrates strong operational resilience characteristics typical of a mature, PE-consolidated GovTech SaaS platform. The company serves 13,000+ local government customer organizations across the U.S. and Canada, reaches 340M+ residents, and reports 98% customer retention. Public-sector customers provide predictable, low-default receivables, and multi-year contracts with high switching costs (RFP procurement cycles, embedded workflows) support recurring revenue stability. The 25+ year operating history, diversified portfolio of 15+ product lines, and successful M&A roll-up execution (Rec1, SeeClickFix, Municode, Optimere/ArchiveSocial/NextRequest) reinforce scale. However, financial transparency is limited: as a privately held Kansas LLC owned by private-equity investors (widely reported to be BV Investment Partners since 2015), CivicPlus does not file with the SEC, publishes no audited financials, and discloses no revenue, EBIT, or equity figures. PE-backed roll-ups commonly carry meaningful LBO/recapitalization debt, and debt service risk is unknown to outside stakeholders. DocAccess itself is an early-stage beta product with immature monetization, operating in a crowded accessibility space (accessiBe, UserWay, AudioEye, Level Access) with ongoing legal debate over whether alternative-HTML approaches satisfy ADA obligations. The 2024 divestiture of Monsido to Acquia signals portfolio pruning pressures on the accessibility line. Score reflects strong operational fundamentals offset by opacity and DocAccess-specific early-stage risk.
Key strengths: 13,000+ government customer organizations with 98% self-reported retention, 25+ year operating history (founded 1994/1998), 950+ employees across multiple U.S. offices, Diversified portfolio of 15+ GovTech product lines, Regulatory tailwind from DOJ Title II ADA rule (WCAG 2.1 AA), Successful M&A roll-up strategy consolidating GovTech niche, Public-sector customer base = predictable, low-default receivables, Reaches 340M+ residents in U.S. and Canada
Risk factors: No audited financial disclosures available (private LLC, no SEC filings), PE ownership likely entails undisclosed LBO/recapitalization leverage, DocAccess is beta-stage product with unproven monetization, Crowded accessibility competitive landscape (accessiBe, UserWay, AudioEye, Level Access), Legal uncertainty over whether alternative-HTML satisfies ADA, Single-vertical concentration (U.S./Canada public sector), Budget-cycle sensitivity to elections and federal grant availability, 2024 Monsido divestiture signals portfolio pressure on accessibility line
Revenue by geography
- United States and Canada: 100%
Workforce by country
- United States: 950
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.