Trust Center

Everything you need to evaluate DocFila for your team or your enterprise: certifications, sub-processors, system status, legal documents, and disclosures — all in one place.

Certifications & attestations

๐Ÿ“‹ SOC 2 Type II

Active audit. Latest report available to Business and Enterprise customers under NDA. Email security@docfila.com.

๐Ÿ‡ช๐Ÿ‡บ GDPR / DPA

Standard Data Processing Addendum (Art. 28) included for every paid plan. EU representative under Art. 27 listed in DPA.

๐Ÿฅ HIPAA BAA

Business Associate Agreement available on request for Business; included by default for Enterprise. PHI workloads on isolated infrastructure.

๐Ÿ“ ISO 27001 (in progress)

Certification path scoped for the next 12 months. Controls already mapped to ISO 27001 Annex A.

Sub-processors

We use a small number of carefully vetted sub-processors. The current list:

โ˜๏ธ Google Cloud Platform

Compute, storage, KMS. US (default) and EU regions. SOC 2, ISO 27001, HIPAA-eligible services.

๐Ÿ”ฅ Firebase

Authentication, real-time sync, hosting. Subset of GCP, same compliance posture.

๐Ÿ’ณ Stripe

Payment processing only. PCI-DSS Level 1.

๐Ÿ“ง Postmark / Resend

Transactional email. SOC 2 Type II.

๐Ÿค– OpenAI & Anthropic

LLM inference for AI features. Zero-data-retention agreements in place. Customer data is never used for training.

๐Ÿ“Š Sentry

Error tracking. PII scrubbed at SDK boundary; document content never sent.

Email us to subscribe to sub-processor change notifications (30-day notice for new additions).

System status & reliability

๐Ÿ“Š Status page

Real-time service status and incident history at status.docfila.com.

โฑ๏ธ SLA

99.9% uptime on Business; up to 99.99% on Enterprise. Service credits for breaches per the MSA.

๐ŸŒ Multi-region

Active-active across multiple GCP regions. Encrypted backups in a secondary region with RPO < 5 min, RTO < 1 hr.

๐Ÿงช DR exercises

Quarterly disaster-recovery drills with full failover testing.

Privacy & data handling

๐Ÿšซ No AI training on your data

Your documents are never used to train models. Period.

๐ŸŒ Data residency

US (default) or EU (Frankfurt + Belgium) on Business and Enterprise plans. Pinned per workspace.

๐Ÿ“ค Data portability

Export everything — documents, metadata, signatures, audit logs — in standard formats at any time.

๐Ÿ—‘๏ธ Deletion guarantee

Hard-delete on request within 30 days. Cryptographic erasure of encrypted backups via key destruction.

Documents

Need something specific?

Procurement reviews, security questionnaires, custom DPAs — we'll work with you.

Contact Trust & Security