Evidence for evaluating DocFila: implemented controls, subprocessors, service status, legal documents, disclosures, and an explicit account of assurance work that is still pending.
DocFila does not currently publish a SOC 2 or ISO 27001 report. Control mappings are implementation evidence, not a certification.
Privacy and data-processing requirements are reviewed during procurement. A DPA applies only when executed by both parties.
Do not upload PHI unless the required workload review and legal agreement have been completed. DocFila does not claim HIPAA certification.
Internal mappings help engineering track security controls. They do not replace an independent audit or customer due diligence.
We use a small number of carefully vetted sub-processors. The current list:
Compute, storage, KMS. US (default) and EU regions. SOC 2, ISO 27001, HIPAA-eligible services.
Authentication, real-time sync, hosting. Subset of GCP, same compliance posture.
Payment processing only. PCI-DSS Level 1.
Transactional email. SOC 2 Type II.
AI providers vary by feature and deployment. Current provider, retention, and training terms are confirmed in the customer data-flow review.
Crash and performance telemetry may be processed by configured diagnostics providers. Customer-specific disclosures are confirmed during procurement.
Email us to subscribe to sub-processor change notifications (30-day notice for new additions).
Real-time service status and incident history at status.docfila.com.
Availability and support commitments apply only when written into the customer order or SLA. Public targets are objectives, not service-credit promises.
Managed-cloud backups and recovery procedures are documented. Customer RPO and RTO commitments require tested evidence and an executed agreement.
Restore and disaster-recovery evidence is published after each completed exercise; planned exercises are never reported as completed.
Your documents are never used to train models. Period.
Deployment location and any residency obligation are confirmed in the customer's architecture review and written agreement.
Export everything — documents, metadata, signatures, audit logs — in standard formats at any time.
Deletion requests, retention rules, and legal holds are supported. Contractual deletion periods are confirmed in the executed DPA or order.