Evidence for evaluating DocFila: implemented controls, subprocessors, service status, legal documents, disclosures, and an explicit account of assurance work that is still pending.
DocFila does not currently publish a SOC 2 or ISO 27001 report. Control mappings are implementation evidence, not a certification.
Privacy and data-processing requirements are reviewed during procurement. A DPA applies only when executed by both parties.
Do not upload PHI unless the required workload review and legal agreement have been completed. DocFila does not claim HIPAA certification.
Internal mappings help engineering track security controls. They do not replace an independent audit or customer due diligence.
We use a small number of carefully vetted sub-processors. The current list:
Compute, storage, KMS. US (default) and EU regions. SOC 2, ISO 27001, HIPAA-eligible services.
Authentication, real-time sync, hosting. Subset of GCP, same compliance posture.
Payment processing only. PCI-DSS Level 1.
Transactional email. SOC 2 Type II.
The AI services that receive document content, all of them Google. No other AI vendor does. Shipped clients hold no model key. Each service, what it is used for, and its retention and residency: AI data handling.
Crash and performance telemetry may be processed by configured diagnostics providers. Customer-specific disclosures are confirmed during procurement.
Email us to subscribe to sub-processor change notifications (30-day notice for new additions).
Real-time service status and incident history at status.docfila.com.
Availability and support commitments apply only when written into the customer order or SLA. Public targets are objectives, not service-credit promises.
Managed-cloud backups and recovery procedures are documented. Customer RPO and RTO commitments require tested evidence and an executed agreement.
Restore and disaster-recovery evidence is published after each completed exercise; planned exercises are never reported as completed.
DocFila does not train, fine-tune, or evaluate any model on your documents, and no dataset is built from them. Provider-side retention and training terms: AI data handling.
Uploaded files are stored in the EU multi-region. The text extracted from them, plus metadata and the search index, is in the United States (nam5), and server processing runs in us-central1. Full breakdown: AI data handling. Residency obligations bind through an executed agreement.
Export everything — documents, metadata, signatures, audit logs — in standard formats at any time.
Deletion requests, retention rules, and legal holds are supported. Contractual deletion periods are confirmed in the executed DPA or order.