Trust Center · Evidence register

Security claims should be inspectable.

This center documents what DocuChase implements, what our infrastructure providers attest to, where data can flow, and which evidence is not yet available.

Published evidence

One place for security due diligence

Last reviewed July 24, 2026

Implemented product controls

These statements describe the current application design. They are not a claim that DocuChase has completed an independent SOC 2 examination.

Documents encrypted before upload

The browser creates a unique AES-256-GCM key per document and uploads ciphertext, not plaintext document content.

Firm key remains wrapped at rest

The RSA private key is password-wrapped in the browser. The plaintext vault password is not sent to the application server.

Firm-scoped authorization

Supabase Row Level Security and server-side ownership checks constrain authenticated access to a firm workspace.

Short-lived document access

Private storage objects are accessed through time-limited signed URLs after authenticated firm-ownership checks.

Assurance boundary

Vercel, Supabase, and other providers maintain their own certifications and controls. Those attestations apply to the provider services in scope; they do not make DocuChase SOC 2 audited, certify a customer firm, or replace a customer's GLBA safeguards program.