DocFila for Business

Built for document-heavy teams. SSO, SCIM user lifecycle, audit exports, retention controls, legal hold, secure signing, scoped APIs, and signed webhooks in one workspace.

Start on the free plan · iPhone, Android, Mac, Windows and the web

Security & Compliance

Your documents are some of the most sensitive data you handle. We treat them that way.

🔐 AES-256 Encryption

Every document is encrypted at rest with AES-256 and in transit with TLS, and the text extracted from it is encrypted again, field by field. Customer-managed keys are on the roadmap, not available today.

🛡️ Verifiable controls

Architecture, control mappings, security rules, and release evidence are available for buyer review. Independent certifications are not claimed without a current report.

🇪🇺 Privacy controls

Retention, deletion workflows, legal hold, access controls, and audit exports support customer privacy programs. Contractual terms are confirmed during procurement.

🏥 Workload review

Regulated workloads require a documented architecture and legal review. No HIPAA or BAA claim applies unless DocFila has executed the required agreement.

🔍 Security validation

Automated security, rules, secret, artifact, API-contract, malware, and release gates run before deployment. Independent testing is reported only when completed.

🚫 Zero AI Training

DocFila never uses your documents to train AI models. Vault items marked Encrypted, or stored with zero-knowledge mode on, are encrypted on the user's device with a key DocFila's servers never receive.

Admin & Identity Controls

🪪 SSO (SAML 2.0 + OIDC)

Connect a SAML 2.0 or OpenID Connect identity provider.

👥 SCIM 2.0 Provisioning

Create, read, filter, update, and deactivate users through SCIM 2.0, with duplicate and organization-owner protection.

📋 Audit Logs

Document and signing events are recorded for review and export. Signature evidence uses a tamper-evident hash chain and completion certificate.

⏳ Custom Retention

Set retention policies per workspace, folder, or document type. Legal hold to freeze deletion during investigations and e-discovery.

🛂 Granular Roles

Owner, Admin, Manager, Member, Viewer, Guest. Per-folder permissions, signature template ownership, and per-feature toggles.

📤 Data Portability

Bulk export of all documents, metadata, signatures, and audit logs in standard formats. Your data is always yours.

Built for the teams that handle the most documents

⚖️ Legal

Contract execution, NDA workflows, tamper-evident signature records via DocFila Verify, and questions about your documents with DocFila Ask. DocFila does not give legal advice.

🏠 Real Estate

Rental agreements with e-signing, scanned disclosure documents, and document packs for each property.

💰 Finance & Accounting

Receipt capture with OCR, invoices and receipts in FinFlow, retention policies, and document packs for period-end files.

🏥 Healthcare

DocFila does not claim HIPAA compliance and does not currently sign Business Associate Agreements. Do not upload patient health information.

👥 HR & People Ops

Offer letter and employment contract templates, document packs, signature requests for acknowledgments, a document vault, and SCIM-driven access lifecycle.

🏗️ Construction & Field Ops

On-site document and receipt scanning on your phone, signed change orders, and document packs.

Onboarding & Support

🚀 Setup help

For Enterprise customers we help configure SSO, SCIM and workspaces. What is included, and when, is agreed in writing.

⚡ Priority Support

Priority email support. Service levels, if any, are agreed in writing in an Enterprise contract; none is offered by default.

🎓 Admin & User Training

Help articles in the app and onboarding help by email from the team that builds DocFila.

Bring DocFila to your team

30-minute demo. We'll walk through SSO, admin controls, and the workflows that fit your team. Custom pricing for 50+ seats.

Book a Demo
Or compare plans →

Frequently Asked Questions

Is DocFila independently certified?

DocFila does not currently claim SOC 2, ISO 27001, or HIPAA certification. We share implemented-control evidence and clearly label independent assurance separately.

Can we use DocFila for regulated data?

Only after confirming the architecture and executing any required legal agreement. Do not upload regulated health data based on marketing copy alone.

Which SSO providers?

SAML 2.0 and OpenID Connect identity providers. SCIM 2.0 is included. We have not published a list of tested providers.

Where is our data stored?

Deployment location and residency requirements are confirmed in your order and architecture review. No regional-residency commitment applies unless written into the agreement.

Can we run a security review?

Yes. We share architecture documentation, control mappings, API documentation, and implemented-control evidence. Independent reports are supplied only when current.

Do you offer Enterprise contracts?

Yes — multi-year terms, an MSA, a DPA, service levels agreed in writing, and volume pricing. Contact sales@docfila.com.