Security at DocFila

Your documents are sensitive. DocFila uses managed-cloud encryption, least-privilege controls, malware scanning, tamper-evident signing evidence, and public vulnerability reporting.

Encryption & data protection

🔐 AES-256 at rest

Every document, signature, embedding, and audit log is encrypted at rest with AES-256. Encryption keys rotated regularly and stored in HSM-backed key management (Google Cloud KMS).

🔒 TLS in transit

Production traffic uses HTTPS with HSTS. Exact protocol negotiation depends on the managed hosting edge and supported client.

🗝️ Key management

Platform-managed encryption keys protect stored cloud data. Customer-managed key options are not promised unless documented in the customer architecture and order.

🛡️ Vault end-to-end encryption

Vault content is encrypted client-side before upload. Even DocFila employees with full database access cannot read it.

Compliance & certifications

📋 Assurance status

DocFila does not currently claim SOC 2, ISO 27001, or HIPAA certification. Implemented controls and mappings are not independent attestations.

🇪🇺 Privacy program

Retention, deletion, legal-hold, access, and audit controls support customer privacy obligations. Contractual terms apply only when executed.

🏥 Regulated workloads

Regulated data requires an architecture and legal review before use. Do not upload PHI unless the required agreement has been executed.

📐 Control mappings

Control mappings support internal readiness and buyer review. Certification will be stated only after an independent auditor issues a current report.

AI & privacy

🚫 Zero training on your data

We never train AI models on your documents. Period. AI features run on your data inference-only, in transient compute, with no logging of content.

🤖 Model isolation

Enterprise customers can run AI in single-tenant inference environments with no shared model context across customers.

👀 No human review of content

DocFila employees do not read your documents to improve products. Automated quality monitoring uses metadata only.

🇨🇳 No PRC dependencies

No model providers, infrastructure, or sub-processors in jurisdictions with mandatory data access laws (PRC, Russia, Iran, North Korea).

Operational security

🔍 Release validation

Automated rules, secret, artifact, API-contract, malware, and regression gates run before deployment. Independent testing is reported only when completed.

📊 Monitoring

Production telemetry and provider alerts support incident detection. Coverage and response commitments are documented in the customer's support terms.

🔄 Backup & recovery

Managed-cloud recovery procedures are documented. RPO, RTO, and exercise-frequency commitments require current test evidence and written terms.

🛂 Least privilege

Production access requires SSO + hardware key + just-in-time approval. All access logged immutably.

Responsible disclosure

Found a security issue? We want to know. Email security@docfila.com with details. PGP key and full policy at /.well-known/security.txt. We aim to respond within 24 hours and patch critical issues within 7 days.

Security reports are triaged by severity. Reward or safe-harbor terms apply only when confirmed in writing for the submitted report.

Want a deeper security review?

Business and Enterprise prospects can request architecture documentation, control mappings, API documentation, and current engineering test evidence.

Request Documents