Trust Center

Evidence for evaluating DocFila: implemented controls, subprocessors, service status, legal documents, disclosures, and an explicit account of assurance work that is still pending.

Assurance status

๐Ÿ“‹ Independent assurance

DocFila does not currently publish a SOC 2 or ISO 27001 report. Control mappings are implementation evidence, not a certification.

๐Ÿ‡ช๐Ÿ‡บ Privacy terms

Privacy and data-processing requirements are reviewed during procurement. A DPA applies only when executed by both parties.

๐Ÿฅ Regulated health data

Do not upload PHI unless the required workload review and legal agreement have been completed. DocFila does not claim HIPAA certification.

๐Ÿ“ Control mapping

Internal mappings help engineering track security controls. They do not replace an independent audit or customer due diligence.

Sub-processors

We use a small number of carefully vetted sub-processors. The current list:

โ˜๏ธ Google Cloud Platform

Compute, storage, KMS. US (default) and EU regions. SOC 2, ISO 27001, HIPAA-eligible services.

๐Ÿ”ฅ Firebase

Authentication, real-time sync, hosting. Subset of GCP, same compliance posture.

๐Ÿ’ณ Stripe

Payment processing only. PCI-DSS Level 1.

๐Ÿ“ง Postmark / Resend

Transactional email. SOC 2 Type II.

๐Ÿค– AI providers

AI providers vary by feature and deployment. Current provider, retention, and training terms are confirmed in the customer data-flow review.

๐Ÿ“Š Diagnostics

Crash and performance telemetry may be processed by configured diagnostics providers. Customer-specific disclosures are confirmed during procurement.

Email us to subscribe to sub-processor change notifications (30-day notice for new additions).

System status & reliability

๐Ÿ“Š Status page

Real-time service status and incident history at status.docfila.com.

โฑ๏ธ Service objectives

Availability and support commitments apply only when written into the customer order or SLA. Public targets are objectives, not service-credit promises.

๐ŸŒ Recovery design

Managed-cloud backups and recovery procedures are documented. Customer RPO and RTO commitments require tested evidence and an executed agreement.

๐Ÿงช Recovery exercises

Restore and disaster-recovery evidence is published after each completed exercise; planned exercises are never reported as completed.

Privacy & data handling

๐Ÿšซ No AI training on your data

Your documents are never used to train models. Period.

๐ŸŒ Data location

Deployment location and any residency obligation are confirmed in the customer's architecture review and written agreement.

๐Ÿ“ค Data portability

Export everything — documents, metadata, signatures, audit logs — in standard formats at any time.

๐Ÿ—‘๏ธ Deletion workflow

Deletion requests, retention rules, and legal holds are supported. Contractual deletion periods are confirmed in the executed DPA or order.

Documents

Need something specific?

Procurement reviews, security questionnaires, custom DPAs — we'll work with you.

Contact Trust & Security