Evidence for evaluating DocFila: implemented controls, subprocessors, service status, legal documents, disclosures, and an explicit account of assurance work that is still pending.
DocFila does not currently publish a SOC 2 or ISO 27001 report. Control mappings are implementation evidence, not a certification.
Privacy and data-processing requirements are reviewed during procurement. A DPA applies only when executed by both parties.
Do not upload PHI unless the required workload review and legal agreement have been completed. DocFila does not claim HIPAA certification.
Internal mappings help engineering track security controls. They do not replace an independent audit or customer due diligence.
The third parties that process customer data, taken from the code. The full register, with data categories and locations, is available on request.
Hosting, database, file storage, and server processing. Files are stored in the EU multi-region; extracted text, metadata, and the search index in the US (nam5); server processing runs in us-central1.
Sign-in, real-time sync, hosting, and push notifications. Crash reports (Crashlytics) and usage statistics (Analytics) are collected only when you, or your organization, allow them.
Payment processing only. Stripe holds its own PCI DSS Level 1 certification; that is Stripe's certification, not DocFila's.
Transactional email: signature requests, transfers, invoices, and invitations, including any attachments you send.
Fallback transactional email, used only when the primary provider is not available.
SMS for appointment reminders and review requests you send: the phone number and the message text.
Subscription status for purchases made in the iOS and Android apps.
Bug reports you choose to send: a reference and redacted technical details. No name, email address, or account id.
The AI services that receive document content, all of them Google. No other AI vendor does. Shipped clients hold no model key. Each service, what it is used for, and its retention and residency: AI data handling.
Email us to be told about changes to this list. Customers with a signed DPA get the notice period set in the DPA.
Service status and incident notices at status.docfila.com, updated by hand during an incident.
Availability and support commitments apply only when written into the customer order or SLA. Public targets are objectives, not service-credit promises.
Database delete protection is on, and Google replicates stored data across zones. Point-in-time recovery, managed backups, and a tested restore are not in place yet, so no RPO or RTO is offered.
Restore and disaster-recovery evidence is published after each completed exercise; planned exercises are never reported as completed.
DocFila does not train, fine-tune, or evaluate any model on your documents, and no dataset is built from them. Provider-side retention and training terms: AI data handling.
Uploaded files are stored in the EU multi-region. The text extracted from them, plus metadata and the search index, is in the United States (nam5), and server processing runs in us-central1. Full breakdown: AI data handling. Residency obligations bind through an executed agreement.
Download your documents, export your account's records as JSON, and export a document's access log as CSV or JSON, at any time.
Deletion requests, retention rules, and legal holds are supported. Contractual deletion periods are confirmed in the executed DPA or order.