Built for document-heavy teams. SSO, SCIM user lifecycle, audit exports, retention controls, legal hold, secure signing, scoped APIs, and signed webhooks in one workspace.
Start on the free plan · iPhone, Android, Mac, Windows and the web
Your documents are some of the most sensitive data you handle. We treat them that way.
Every document is encrypted at rest with AES-256 and in transit with TLS, and the text extracted from it is encrypted again, field by field. Customer-managed keys are on the roadmap, not available today.
Architecture, control mappings, security rules, and release evidence are available for buyer review. Independent certifications are not claimed without a current report.
Retention, deletion workflows, legal hold, access controls, and audit exports support customer privacy programs. Contractual terms are confirmed during procurement.
Regulated workloads require a documented architecture and legal review. No HIPAA or BAA claim applies unless DocFila has executed the required agreement.
Automated security, rules, secret, artifact, API-contract, malware, and release gates run before deployment. Independent testing is reported only when completed.
DocFila never uses your documents to train AI models. Vault items marked Encrypted, or stored with zero-knowledge mode on, are encrypted on the user's device with a key DocFila's servers never receive.
Connect a SAML 2.0 or OpenID Connect identity provider.
Create, read, filter, update, and deactivate users through SCIM 2.0, with duplicate and organization-owner protection.
Document and signing events are recorded for review and export. Signature evidence uses a tamper-evident hash chain and completion certificate.
Set retention policies per workspace, folder, or document type. Legal hold to freeze deletion during investigations and e-discovery.
Owner, Admin, Manager, Member, Viewer, Guest. Per-folder permissions, signature template ownership, and per-feature toggles.
Bulk export of all documents, metadata, signatures, and audit logs in standard formats. Your data is always yours.
Contract execution, NDA workflows, tamper-evident signature records via DocFila Verify, and questions about your documents with DocFila Ask. DocFila does not give legal advice.
Rental agreements with e-signing, scanned disclosure documents, and document packs for each property.
Receipt capture with OCR, invoices and receipts in FinFlow, retention policies, and document packs for period-end files.
DocFila does not claim HIPAA compliance and does not currently sign Business Associate Agreements. Do not upload patient health information.
Offer letter and employment contract templates, document packs, signature requests for acknowledgments, a document vault, and SCIM-driven access lifecycle.
On-site document and receipt scanning on your phone, signed change orders, and document packs.
For Enterprise customers we help configure SSO, SCIM and workspaces. What is included, and when, is agreed in writing.
Priority email support. Service levels, if any, are agreed in writing in an Enterprise contract; none is offered by default.
Help articles in the app and onboarding help by email from the team that builds DocFila.
DocFila does not currently claim SOC 2, ISO 27001, or HIPAA certification. We share implemented-control evidence and clearly label independent assurance separately.
Only after confirming the architecture and executing any required legal agreement. Do not upload regulated health data based on marketing copy alone.
SAML 2.0 and OpenID Connect identity providers. SCIM 2.0 is included. We have not published a list of tested providers.
Deployment location and residency requirements are confirmed in your order and architecture review. No regional-residency commitment applies unless written into the agreement.
Yes. We share architecture documentation, control mappings, API documentation, and implemented-control evidence. Independent reports are supplied only when current.
Yes — multi-year terms, an MSA, a DPA, service levels agreed in writing, and volume pricing. Contact sales@docfila.com.