Enterprise-grade security controls protecting your data at every layer, built to meet SOC 2 Type II standards.
Six pillars of security built into every layer of the FileRidge platform.
All sensitive data is encrypted using AES-256-GCM at rest and TLS 1.2+ in transit. Field-level encryption with versioned ciphertext supports seamless key rotation.
Enterprise authentication with single sign-on, multi-factor authentication support, and automatic session management with secure token validation.
Granular role levels enforce the principle of least privilege, ensuring users only access what they need for their specific responsibilities.
Every action generates an immutable audit record enforced at the database level. Logs are retained for 3+ years with full request correlation and user attribution.
Soft deletes with configurable retention periods prevent data loss. Legal hold enforcement cascades to child records, and automated cleanup runs with full audit trails.
Hosted on Google Cloud Platform in US regions with daily automated backups, point-in-time recovery, and rate limiting to prevent abuse.
Enterprise-grade identity management with granular role-based permissions at every level.
Every meaningful action is recorded in an immutable, tamper-evident audit trail.
Clear, documented retention policies designed for regulatory compliance and data protection.
| Data Type | Retention | Basis |
|---|---|---|
| Audit Logs | 3 years | SOC 2 |
| Claims | 7 years | Insurance Reg. |
| Invoices | 7 years | Insurance Reg. |
| Deleted Records | 30 days | Grace Period |
How FileRidge's controls map to the five SOC 2 trust service criteria. We are not yet formally audited or certified—this reflects the security standards we build to.
Protection against unauthorized access through encryption, access controls, rate limiting, security headers, and continuous monitoring.
Designed for 99.9% uptime with automated failover, redundant infrastructure on Google Cloud, and daily backups with point-in-time recovery.
Automated fee calculations, comprehensive audit trails, data validation at every boundary, and immutable transaction records.
Field-level AES-256 encryption, strict multi-tenant data isolation, role-based access control, and sensitive data redaction in logs.
Documented data retention policies, right to deletion, privacy policy, data portability support, and US-only data residency.
Built on Google Cloud Platform with enterprise-grade reliability and US-based data residency.
Enterprise-grade cloud infrastructure trusted by millions of businesses worldwide.
All data stored and processed within United States regions. Your data never leaves US soil.
Daily automated backups with 30-day retention and 7-day point-in-time recovery window.
Development and production environments are fully separated with no data transfer between them.
Layered rate limiting protects against abuse and denial-of-service attacks.
We're happy to discuss our security practices, respond to security questionnaires, or provide additional documentation about how we protect your data.