AI document management for regulated teams
AI-Powered Document Management System
Store, find, sign, approve and prove — every document, in one secure system. Built for organisations that answer to a regulator.
Built to support
- Built to support:ISO/IEC 27001
- Built to support:SOC 2 Type II
- Built to support:GDPR
- Built to support:HIPAA
- Built to support:Cyber Essentials

DocumentMS is a document management system: software that stores every file in one versioned, permission-controlled repository, makes it findable through OCR and metadata search, routes it for approval and signature, and records an immutable audit trail of every action taken on it.
One platform, eleven modules
Everything a controlled document needs, in one place
Document management
A versioned central repository organised by category, folder and physical location, with check-out/check-in, unlimited version history, automatic document numbering and content-hash duplicate detection.How document management worksOCR & full-text search
Optical character recognition reads scanned images and image-only PDFs so their text becomes searchable, then combines that text with custom metadata in a single global search.How ocr & full-text search worksElectronic signatures
Request signatures from colleagues or from external parties through a secure public signing link, with saved signatures, a full request history and DocuSign integration where it is already in use.How electronic signatures worksWorkflow automation
Configurable workflow templates define the steps and approval chain a document must clear. Instances track step history, reassignment and reminders, and policy acknowledgement is recorded per user.How workflow automation worksSecurity & compliance
Granular role-based access control per module, two-factor authentication, SSO through OIDC, 256-bit encryption, IP restrictions, triple backups and break-glass emergency access.How security & compliance worksAudit trails & reporting
Every view, download, edit, share and deletion is written to an immutable audit trail, and dashboards report storage consumption, user activity, duplicates and pending signatures.How audit trails & reporting works
Built for regulated industries
Configured for the evidence your regulator asks for
- HealthcareHIPAA & HITECH
- Financial servicesSEC 17a-4 & FINRA
- LegalPrivilege & ethical walls
- Construction & engineeringISO 19650
- ManufacturingIATF 16949 & ISO 9001
- GovernmentPublic records & FOI
- EducationFERPA & safeguarding
- Energy & utilitiesNERC CIP & permits
- Pharma & life sciences21 CFR Part 11
- LogisticsCustoms & proof of delivery
AI that reduces filing, not oversight
Classification, extraction, summarisation and semantic search
Document classification
Incoming files are proposed a category, folder and document type based on their content, so an invoice arriving by email lands in the right place without a human sorting step.
Data extraction
Named fields — supplier, contract value, renewal date, policy number — are extracted into metadata that filters and reports can use, with the source text retained for verification.
Summarisation
Long agreements and reports get a short, structured summary so a reviewer can decide whether they need to open the full document before an approval deadline.
Semantic search
Search by meaning as well as by string: "the lease that renews in Q3" finds the right document even when those words never appear in it.
Security by default
Controls an auditor can inspect, not just claims
- 256-bit encryptionDocuments encrypted at rest and in transit over TLS.
- Two-factor authenticationTOTP-based 2FA, enforceable per role.
- Single sign-onOIDC SSO with Microsoft Entra ID, Okta and Google Workspace.
- IP restrictionsRestrict access to known networks per user or role.
- Custom password policyLength, complexity, rotation and reuse rules you set.
- Triple backupsThree independent backup copies with documented restore tests.
- Administrator-only recycle binDeletions are recoverable, and only administrators can see them.
- Immutable audit trailAppend-only record of every action, exportable for evidence.
- Break-glass accessTime-boxed emergency access that is logged and alerted on.
From draft to disposition
One controlled path for every document
Step 1: Captured
Uploaded, imported from a watched mailbox, scanned, or generated from a template — then classified, numbered and hashed against existing files.
Step 2: Reviewed
Routed to the reviewers your workflow template defines, with reminders, reassignment and a recorded comment at every step.
Step 3: Approved
Approval is captured against a named user at a timestamp, the version is locked, and superseded versions stay in history rather than disappearing.
Step 4: Signed & retained
Signature requests go to internal or external signers, and the retention rule attached to the document type governs when it is reviewed for disposition.

What the record shows afterwards
- Who approved each step, at what time, from what address
- Which version was approved, and which versions it superseded
- Every signature request sent, opened, declined or completed
- Each permission change, with the administrator who made it
- The retention rule in force and the next disposition review date
Fits the stack you already run
Microsoft 365, Outlook, DocuSign, S3, Azure and a documented REST API
- Microsoft 365Open and edit in Word, Excel and PowerPoint with the version returned to DocumentMS
- Outlook add-inFile an email and its attachments into a folder without leaving the mailbox
- DocuSignSend for signature through DocuSign and store the completed envelope
- Amazon S3Use an S3 bucket in your own account and region as the storage backend
- Azure Blob StorageStore documents in Azure with your own keys and region selection
- Microsoft Entra IDOIDC single sign-on with group-to-role mapping
Outcomes
What changes after implementation
Document retrieval time
Finding a document becomes a search rather than a hunt through folder trees and someone’s memory of where it was filed. Full-text search reaches inside scanned pages, so the archive is as searchable as the current work.
Failed audit samples
Evidence stops being assembled the week before an audit. The approval, the version and the acknowledgement are recorded as work happens, so producing a sample is a filter rather than a project.
Duplicated storage
One current version, with the history behind it, instead of five near-identical copies across a shared drive, an inbox and two laptops. Check-out makes the current version unambiguous rather than conventional.
Evaluating options
Honest comparisons, including where we are not the answer
Frequently asked questions
What is a document management system?
A document management system (DMS) is software that captures, stores, versions, secures and retrieves an organisation's documents from one repository. Unlike file sync tools, a DMS adds metadata, controlled approval workflows, retention rules and an audit trail that records every action taken on a document.
How is DocumentMS different from SharePoint or Google Drive?
SharePoint and Google Drive are strong at collaborative authoring and file sharing. DocumentMS is built around document control: versioned records with mandatory metadata, configurable approval chains, retention schedules with disposition, per-module role-based permissions and an immutable audit trail designed to be handed to an auditor. Teams commonly run both.
Can DocumentMS search inside scanned paper documents?
Yes. Optical character recognition runs on uploaded images and image-only PDFs, extracting their text into the search index. Scanned contracts, signed delivery notes and archived correspondence become findable by their contents as well as by filename and metadata.
Where is our data stored, and can we choose the region?
Storage is configurable at runtime between local disk, Amazon S3 and Azure Blob Storage, which means the hosting region follows the backend you select. Platform-managed storage runs in Ireland, Frankfurt, N. Virginia, Cape Town or Singapore, fixed when the tenant is provisioned; on Enterprise you can point it at your own bucket in any region.
Does DocumentMS support electronic signatures that hold up legally?
DocumentMS captures signatures from internal users and from external parties through secure signing links, and records the full request and signing history as evidence. It also integrates with DocuSign where an organisation has already standardised on it. Legal weight depends on your jurisdiction — our guide to electronic signature legality covers eIDAS, ESIGN/UETA and eleven other regimes.
How does the audit trail actually work?
Every action against a document — view, download, edit, version, share, signature request, permission change, deletion and restore — is appended to a record that cannot be edited from the application. Entries carry the acting user, timestamp, source IP and the affected version, and can be exported for an audit sample.
How long does implementation take?
A single-department rollout with an existing folder structure and SSO usually runs in weeks rather than months; a multi-entity migration off network shares or SharePoint takes longer because taxonomy and retention decisions have to be made before content moves. Our implementation checklist sets out the sequence we recommend.
What does DocumentMS cost?
DocumentMS is licensed per user per month across three tiers, with storage included and metered overage above the tier allowance. Security features are included at every tier rather than gated behind an enterprise plan.
More definitions and background in the document management glossary and the implementation guides.