Built to SOC 2 Type II Standards

FileRidge has implemented comprehensive security controls aligned with SOC 2 Type II trust service criteria. Our platform is architected for compliance from the ground up—security isn't an afterthought, it's foundational to how we build. FileRidge is not yet SOC 2 certified; these controls reflect how the platform is built today.

256
Bit AES-GCM Encryption
3yr
Audit Log Retention
99.9%
Uptime Target
US
Region Data Storage

How We Protect Your Data

Six pillars of security built into every layer of the FileRidge platform.

Data Encryption

All data is encrypted at rest with AES-256 (managed by our infrastructure providers: Neon for the database, Cloudflare R2 for files) and encrypted in transit with TLS 1.2+.

AES-256 TLS 1.2+ At Rest

Authentication & Identity

Enterprise authentication with single sign-on, multi-factor authentication support, and automatic session management with secure token validation.

Enterprise SSO MFA Session Mgmt

Role-Based Access Control

Granular role levels enforce the principle of least privilege, ensuring users only access what they need for their specific responsibilities.

RBAC Least Privilege Per-Org Controls

Immutable Audit Logging

Every action generates an append-only audit record through a single enforced code path. Records are written once and not updated, and inherit the durability and point-in-time recovery of our managed database. Logs are retained for 3+ years with full request correlation and user attribution.

Immutable 3yr Retention Correlated

Data Protection

Soft deletes preserve records for a grace period rather than removing them immediately. The data model carries legal-hold fields that block deletion of held records, audit-log retention is enforced by an automated scheduled purge, and all deletion events are recorded in the audit trail.

Soft Delete Legal Hold 7yr Claims

Infrastructure Security

Runs on Cloudflare's global edge network with Neon Postgres and Cloudflare R2 object storage, with point-in-time database recovery and rate limiting to prevent abuse.

Cloudflare Neon Postgres Rate Limiting

Identity & Authorization

Enterprise-grade identity management with granular role-based permissions at every level.

Authentication

  • Enterprise single sign-on (SSO) support
  • Multi-factor authentication
  • Automatic session expiry and renewal
  • Authentication rate limiting and bot detection (via WorkOS-hosted login)

Authorization

  • Granular role-based permissions with multiple access tiers
  • Principle of least privilege across all endpoints
  • Per-organization feature and access controls
  • Multi-tenant data isolation on every query

Comprehensive Audit Logging

Every meaningful action is recorded in an append-only audit trail enforced by application design.

Append-Only by Design

  • Every mutation flows through one enforced audit code path
  • Records are written once and never updated after creation
  • Sensitive data automatically redacted before storage

Long-Term Retention

  • Minimum 3-year retention period
  • Exceeds SOC 2 audit log requirements
  • Automated lifecycle management after retention period

Comprehensive Coverage

  • Authentication and authorization events
  • All data access and modification operations
  • Security events and access denials
  • End-to-end request correlation for traceability

Data Retention & Protection

Clear, documented retention policies designed for regulatory compliance and data protection.

Retention Schedule

Data Type Retention Basis
Audit Logs 3 years SOC 2
Claims 7 years Insurance Reg.
Invoices 7 years Insurance Reg.
Deleted Records 30 days Grace Period

Protection Mechanisms

  • Soft Delete: Records are marked for deletion, not immediately removed
  • Legal Hold: Records carry legal-hold fields that block deletion while a hold is set
  • Automated Retention: Audit-log retention is enforced by an automated, scheduled purge job
  • Audit Trail: All deletion events are logged for accountability
  • Role-Based Authorization: Deletion and legal-hold changes are gated by role-based permissions

SOC 2 Trust Service Criteria

How FileRidge's controls map to the five SOC 2 trust service criteria. We are not yet formally audited or certified—this reflects the security standards we build to.

Security

Protection against unauthorized access through encryption, access controls, rate limiting, security headers, and continuous monitoring.

Availability

Designed for 99.9% uptime on Cloudflare's globally distributed network, with Neon Postgres point-in-time recovery.

Processing Integrity

Automated fee calculations, comprehensive audit trails, data validation at every boundary, and immutable transaction records.

Confidentiality

AES-256 encryption at rest, strict multi-tenant data isolation, role-based access control, and sensitive data redaction in logs.

Privacy

Documented data retention policies, right to deletion, privacy policy, data portability support, and US-region data storage.

Cloud Infrastructure

Built on Cloudflare's global edge network with Neon Postgres and Cloudflare R2, engineered for enterprise-grade reliability and resilience.

Cloudflare Edge Network

Globally distributed edge compute and storage with built-in DDoS protection, serving requests close to your users.

US-Region Data Storage

Your application database and stored files are hosted in United States cloud regions (Neon Postgres and Cloudflare R2). Application requests are processed on Cloudflare's global edge network; persistent customer data is stored in the US.

Automated Backups

Daily automated backups with 30-day retention and 7-day point-in-time recovery window.

Isolated Environments

Development and production environments are fully separated with no data transfer between them.

Rate Limiting

Cloudflare platform-layer DDoS protection runs before application code; application-layer rate limiting (per-IP and per-tenant tiers) protects against credential stuffing and API abuse.

Have Security Questions?

We're happy to discuss our security practices, respond to security questionnaires, or provide additional documentation about how we protect your data.