Compliance & Governance

Document sharing that satisfies auditors

Full audit trails, identity verification, immutable access logs, and exportable reports — built for teams with real compliance requirements.

Compliance Frameworks

Aligned to global standards

FileLink's controls are designed to support the leading compliance frameworks used by legal, financial, and enterprise teams worldwide.

GDPR

European Union

FileLink supports GDPR compliance with explicit identity verification, data minimisation by design, access revocation on request, and detailed processing records.

  • Documented consent trail via OTP
  • Data access logs available for audits
  • Link revocation = effective right to access withdrawal
  • No third-party tracking in viewer

SOC 2 Type II

United States

Controls aligned to the Security, Availability, and Confidentiality trust service criteria. Audit logs, encryption, access control, and monitoring are built-in.

  • Encryption at rest and in transit
  • Role-based access to file management
  • Immutable audit logs for every access event
  • 99.9% availability SLA

ISO 27001

International

Our security controls are aligned to ISO 27001 information security management best practices, including asset management, access control, and incident logging.

  • Access control policy enforcement
  • Cryptographic controls (AES-256)
  • Audit trail for information access
  • Supplier security evaluation

Global Standards

Worldwide

FileLink is designed to support compliance with leading global data protection standards. Our controls map to common requirements across jurisdictions, including identity verification, access logging, and data encryption.

  • Identity verification for data access
  • Access logs retained per retention policy
  • Data processing records available
  • Configurable retention and deletion policies
Audit Trail

Every access event, fully documented

Your compliance team needs evidence. FileLink provides a complete, exportable record of every document interaction.

Per-session audit logs

Every view session is logged with recipient identity, IP, device, duration, and timestamp.

Exportable reports

Export audit logs as CSV or PDF for external auditors, legal discovery, or compliance filings.

Geographic tracking

IP geolocation records the country and region of every access event.

Access anomaly detection

Unusual access patterns (multiple geographies, rapid sessions) surface in your dashboard.

Immutable log entries

Audit logs cannot be edited or deleted by account holders — ensuring integrity for legal proceedings.

Chain of custody

Prove exactly who received, viewed, and when — creating a defensible chain of custody for sensitive documents.

Data residency & subprocessors

FileLink is operated by Docully SaaS Technologies. Infrastructure is hosted on Supabase (backed by AWS). All data is encrypted in transit and at rest. Enterprise customers can request a full list of subprocessors and detailed security documentation.

Data storage
Encrypted cloud storage (AWS)
Security docs
Yes — contact us to request
Encryption
AES-256 at rest, TLS in transit

Need a compliance review?

Our team is available to walk your legal and compliance team through FileLink's controls, answer audit questions, and provide documentation.