Skip to Content
Security and compliance

Audit readiness is the default, not the exception

Docufella is built so that every action is timestamped, every approval recorded and every document protected in transit, at rest and after filing. Deploy it in the cloud region you choose, in your own data centre or air-gapped, with the same controls in each.

Request the security guide
Platform controls

Security built into the product

Encryption

TLS 1.2 or higher enforced for all traffic. AES-256 encryption at rest for documents and encrypted backups. Database encryption at rest enabled per customer policy.

Tamper-evident storage

Blockchain-based file integrity verification proves that a filed document has not been altered, supporting legal admissibility and audit defence.

Access control

Role-based granular permissions down to document and metadata level, covering view, edit, export, share and delete. Separation of duties enforced in workflows.

Identity

Single sign-on with Microsoft Entra ID, Okta and SAML 2.0 providers. Multi-factor authentication for privileged access. Optional privileged access management integration.

Immutable audit trail

Every view, edit, download, share, approval and configuration change is logged with user, timestamp and origin. Complete audit reports on demand.

Retention and disposal

Rule-based retention policies, document expiry alerts and controlled disposal so records are kept exactly as long as regulation requires.

Controlled sharing

External sharing through expiring links with download tracking and revocation. No anonymous access to the repository.

Network protection

Only HTTPS ports exposed, databases never public, IP allow-listing, VPN and zero-trust access options, and web application firewall support.

Hardened containers

Services run as non-root with least privilege. Documents are stored on access-controlled persistent volumes outside the containers.

Secure development

How the software is built and shipped

  • Mandatory static code analysis: no code is promoted to production without passing defined quality and security thresholds.
  • Mandatory container image scanning for vulnerabilities before any image is shipped. Scan reports available on request.
  • Internal vulnerability assessment and penetration testing before every major release.
  • Security patches included in support for all deployments.
  • Documented shared responsibility model across Docufella, the customer's IT team and the cloud provider.
Data residency

Your data, where your policy says it must be

  • Cloud deployments on AWS or Azure in the region you select.
  • On-premise deployment in your data centre, including fully air-gapped environments.
  • Hybrid deployment with documents on your own storage and the application in the cloud.
  • On-premise AI models so that document content never leaves your network when required.
  • Your documents are indexed for AI retrieval, never used to train shared models.
Standards alignment

Designed to support your compliance programme

Docufella's architecture, controls and practices are aligned with recognised frameworks. Formal certification and audit evidence are produced within each customer's deployment environment, and we support that work with control mappings and documentation.

FrameworkHow Docufella supports it
ISO/IEC 27001Control mapping document covering access control, cryptography, operations security, logging and supplier relationships.
SOC 2 Trust Services CriteriaArchitecture and controls aligned with security, availability and confidentiality criteria. Formal SOC 2 attestation is on our compliance roadmap.
GDPR and data protection lawsEncryption, access logging, retention and disposal controls, and deployment options that keep personal data in-region.
OWASP Top 10Secure development lifecycle with static analysis, dependency and image scanning and pre-release penetration testing.
Sector requirementsAudit trail, separation of duties and retention features used by customers operating under financial, quality and regulatory audit regimes.

Docufella does not currently hold third-party certifications. We state alignment, not certification, and share our control documentation with prospective customers under NDA.

Support and SLA

SLA-backed support with severity-based response and resolution targets, help desk ticketing, email and remote assistance, and a named escalation contact.

Backup and recovery

Automated snapshots and encrypted backups in cloud deployments; documented backup runbooks and optional managed backup for on-premise.

Monitoring

Application and infrastructure metrics, task queue monitoring and optional runtime threat detection with alerting to your operations team.

Need the detail for a security review?

Request the Security Architecture and Hardening Guide, the ISO 27001 control mapping and the deployment architecture document.

Request documents Book a demo