Trust Center

Evidence for evaluating DocFila: implemented controls, subprocessors, service status, legal documents, disclosures, and an explicit account of assurance work that is still pending.

Assurance status

๐Ÿ“‹ Independent assurance

DocFila does not currently publish a SOC 2 or ISO 27001 report. Control mappings are implementation evidence, not a certification.

๐Ÿ‡ช๐Ÿ‡บ Privacy terms

Privacy and data-processing requirements are reviewed during procurement. A DPA applies only when executed by both parties.

๐Ÿฅ Regulated health data

Do not upload PHI unless the required workload review and legal agreement have been completed. DocFila does not claim HIPAA certification.

๐Ÿ“ Control mapping

Internal mappings help engineering track security controls. They do not replace an independent audit or customer due diligence.

Sub-processors

The third parties that process customer data, taken from the code. The full register, with data categories and locations, is available on request.

โ˜๏ธ Google Cloud Platform

Hosting, database, file storage, and server processing. Files are stored in the EU multi-region; extracted text, metadata, and the search index in the US (nam5); server processing runs in us-central1.

๐Ÿ”ฅ Firebase

Sign-in, real-time sync, hosting, and push notifications. Crash reports (Crashlytics) and usage statistics (Analytics) are collected only when you, or your organization, allow them.

๐Ÿ’ณ Stripe

Payment processing only. Stripe holds its own PCI DSS Level 1 certification; that is Stripe's certification, not DocFila's.

๐Ÿ“ง Resend

Transactional email: signature requests, transfers, invoices, and invitations, including any attachments you send.

๐Ÿ“จ Twilio SendGrid

Fallback transactional email, used only when the primary provider is not available.

๐Ÿ’ฌ Infobip

SMS for appointment reminders and review requests you send: the phone number and the message text.

๐Ÿ“ฑ RevenueCat

Subscription status for purchases made in the iOS and Android apps.

๐Ÿž GitHub

Bug reports you choose to send: a reference and redacted technical details. No name, email address, or account id.

๐Ÿค– Google — Gemini, Vertex AI, Firebase AI Logic

The AI services that receive document content, all of them Google. No other AI vendor does. Shipped clients hold no model key. Each service, what it is used for, and its retention and residency: AI data handling.

Email us to be told about changes to this list. Customers with a signed DPA get the notice period set in the DPA.

System status & reliability

๐Ÿ“Š Status page

Service status and incident notices at status.docfila.com, updated by hand during an incident.

โฑ๏ธ Service objectives

Availability and support commitments apply only when written into the customer order or SLA. Public targets are objectives, not service-credit promises.

๐ŸŒ Recovery design

Database delete protection is on, and Google replicates stored data across zones. Point-in-time recovery, managed backups, and a tested restore are not in place yet, so no RPO or RTO is offered.

๐Ÿงช Recovery exercises

Restore and disaster-recovery evidence is published after each completed exercise; planned exercises are never reported as completed.

Privacy & data handling

๐Ÿšซ No AI training on your data

DocFila does not train, fine-tune, or evaluate any model on your documents, and no dataset is built from them. Provider-side retention and training terms: AI data handling.

๐ŸŒ Data location

Uploaded files are stored in the EU multi-region. The text extracted from them, plus metadata and the search index, is in the United States (nam5), and server processing runs in us-central1. Full breakdown: AI data handling. Residency obligations bind through an executed agreement.

๐Ÿ“ค Data portability

Download your documents, export your account's records as JSON, and export a document's access log as CSV or JSON, at any time.

๐Ÿ—‘๏ธ Deletion workflow

Deletion requests, retention rules, and legal holds are supported. Contractual deletion periods are confirmed in the executed DPA or order.

Documents

Need something specific?

Procurement reviews, security questionnaires, custom DPAs — we'll work with you.

Contact Trust & Security