Audit readiness is the default, not the exception
Docufella is built so that every action is timestamped, every approval recorded and every document protected in transit, at rest and after filing. Deploy it in the cloud region you choose, in your own data centre or air-gapped, with the same controls in each.
Request the security guideSecurity built into the product
Encryption
TLS 1.2 or higher enforced for all traffic. AES-256 encryption at rest for documents and encrypted backups. Database encryption at rest enabled per customer policy.
Tamper-evident storage
Blockchain-based file integrity verification proves that a filed document has not been altered, supporting legal admissibility and audit defence.
Access control
Role-based granular permissions down to document and metadata level, covering view, edit, export, share and delete. Separation of duties enforced in workflows.
Identity
Single sign-on with Microsoft Entra ID, Okta and SAML 2.0 providers. Multi-factor authentication for privileged access. Optional privileged access management integration.
Immutable audit trail
Every view, edit, download, share, approval and configuration change is logged with user, timestamp and origin. Complete audit reports on demand.
Retention and disposal
Rule-based retention policies, document expiry alerts and controlled disposal so records are kept exactly as long as regulation requires.
Controlled sharing
External sharing through expiring links with download tracking and revocation. No anonymous access to the repository.
Network protection
Only HTTPS ports exposed, databases never public, IP allow-listing, VPN and zero-trust access options, and web application firewall support.
Hardened containers
Services run as non-root with least privilege. Documents are stored on access-controlled persistent volumes outside the containers.
How the software is built and shipped
- Mandatory static code analysis: no code is promoted to production without passing defined quality and security thresholds.
- Mandatory container image scanning for vulnerabilities before any image is shipped. Scan reports available on request.
- Internal vulnerability assessment and penetration testing before every major release.
- Security patches included in support for all deployments.
- Documented shared responsibility model across Docufella, the customer's IT team and the cloud provider.
Your data, where your policy says it must be
- Cloud deployments on AWS or Azure in the region you select.
- On-premise deployment in your data centre, including fully air-gapped environments.
- Hybrid deployment with documents on your own storage and the application in the cloud.
- On-premise AI models so that document content never leaves your network when required.
- Your documents are indexed for AI retrieval, never used to train shared models.
Designed to support your compliance programme
Docufella's architecture, controls and practices are aligned with recognised frameworks. Formal certification and audit evidence are produced within each customer's deployment environment, and we support that work with control mappings and documentation.
| Framework | How Docufella supports it |
|---|---|
| ISO/IEC 27001 | Control mapping document covering access control, cryptography, operations security, logging and supplier relationships. |
| SOC 2 Trust Services Criteria | Architecture and controls aligned with security, availability and confidentiality criteria. Formal SOC 2 attestation is on our compliance roadmap. |
| GDPR and data protection laws | Encryption, access logging, retention and disposal controls, and deployment options that keep personal data in-region. |
| OWASP Top 10 | Secure development lifecycle with static analysis, dependency and image scanning and pre-release penetration testing. |
| Sector requirements | Audit trail, separation of duties and retention features used by customers operating under financial, quality and regulatory audit regimes. |
Docufella does not currently hold third-party certifications. We state alignment, not certification, and share our control documentation with prospective customers under NDA.
Support and SLA
SLA-backed support with severity-based response and resolution targets, help desk ticketing, email and remote assistance, and a named escalation contact.
Backup and recovery
Automated snapshots and encrypted backups in cloud deployments; documented backup runbooks and optional managed backup for on-premise.
Monitoring
Application and infrastructure metrics, task queue monitoring and optional runtime threat detection with alerting to your operations team.
Need the detail for a security review?
Request the Security Architecture and Hardening Guide, the ISO 27001 control mapping and the deployment architecture document.
Request documents Book a demo