Trust Center · Evidence register
Security claims should be inspectable.
This center documents what DocuChase implements, what our infrastructure providers attest to, where data can flow, and which evidence is not yet available.
Published evidence
One place for security due diligence
Last reviewed July 24, 2026
Security architecture brief
Encryption flow, access model, trust boundaries, threat assumptions, and shared responsibilities.
Review evidenceSubprocessors & residency
The services that process account, communications, billing, and agent data—and what they do not receive.
Review evidencePublic service status
A live view of upstream provider health with a clear distinction between provider and DocuChase availability.
Review evidenceCustomer evidence policy
The approval and measurement standard required before a logo, quote, or case-study result can be published.
Review evidenceImplemented product controls
These statements describe the current application design. They are not a claim that DocuChase has completed an independent SOC 2 examination.
Documents encrypted before upload
The browser creates a unique AES-256-GCM key per document and uploads ciphertext, not plaintext document content.
Firm key remains wrapped at rest
The RSA private key is password-wrapped in the browser. The plaintext vault password is not sent to the application server.
Firm-scoped authorization
Supabase Row Level Security and server-side ownership checks constrain authenticated access to a firm workspace.
Short-lived document access
Private storage objects are accessed through time-limited signed URLs after authenticated firm-ownership checks.
Assurance boundary
Vercel, Supabase, and other providers maintain their own certifications and controls. Those attestations apply to the provider services in scope; they do not make DocuChase SOC 2 audited, certify a customer firm, or replace a customer's GLBA safeguards program.