Your documents are sensitive. DocFila uses managed-cloud encryption, least-privilege controls, malware scanning, tamper-evident signing evidence, and public vulnerability reporting.
Every document, signature, embedding, and audit log is encrypted at rest with AES-256. Encryption keys rotated regularly and stored in HSM-backed key management (Google Cloud KMS).
Production traffic uses HTTPS with HSTS. Exact protocol negotiation depends on the managed hosting edge and supported client.
Platform-managed encryption keys protect stored cloud data. Customer-managed key options are not promised unless documented in the customer architecture and order.
Vault content is encrypted client-side before upload. Even DocFila employees with full database access cannot read it.
DocFila does not currently claim SOC 2, ISO 27001, or HIPAA certification. Implemented controls and mappings are not independent attestations.
Retention, deletion, legal-hold, access, and audit controls support customer privacy obligations. Contractual terms apply only when executed.
Regulated data requires an architecture and legal review before use. Do not upload PHI unless the required agreement has been executed.
Control mappings support internal readiness and buyer review. Certification will be stated only after an independent auditor issues a current report.
We never train AI models on your documents. Period. AI features run on your data inference-only, in transient compute, with no logging of content.
Enterprise customers can run AI in single-tenant inference environments with no shared model context across customers.
DocFila employees do not read your documents to improve products. Automated quality monitoring uses metadata only.
No model providers, infrastructure, or sub-processors in jurisdictions with mandatory data access laws (PRC, Russia, Iran, North Korea).
Automated rules, secret, artifact, API-contract, malware, and regression gates run before deployment. Independent testing is reported only when completed.
Production telemetry and provider alerts support incident detection. Coverage and response commitments are documented in the customer's support terms.
Managed-cloud recovery procedures are documented. RPO, RTO, and exercise-frequency commitments require current test evidence and written terms.
Production access requires SSO + hardware key + just-in-time approval. All access logged immutably.
Found a security issue? We want to know. Email security@docfila.com with details. PGP key and full policy at /.well-known/security.txt. We aim to respond within 24 hours and patch critical issues within 7 days.
Security reports are triaged by severity. Reward or safe-harbor terms apply only when confirmed in writing for the submitted report.