SOC 2 is a roadmap item, not a badge we're wearing.
txtfetch is not SOC 2 certified today. Here's the honest scope of what that would take, and what we already do while we get there.
not certified today
txtfetch has not completed a SOC 2 Type II audit. Anyone telling you otherwise about a pre-launch product should be treated with suspicion — we'd rather say "not yet" than imply a badge we haven't earned.
Planned scope
The intended scope is a SOC 2 Type II report covering the Security and Availability Trust Services Criteria for the extraction API and its supporting AWS infrastructure. Confidentiality would extend naturally from the no-content-retention posture described at /security.
Gaps between today and an audit-ready state
- Formal risk assessment and control documentation across the Trust Services Criteria (security, availability, confidentiality).
- Automated dependency and runtime vulnerability scanning wired into CI (currently a manual process — see /security).
- Independent third-party audit of controls over a defined observation period.
- Formal vendor-management and sub-processor review process (today: a maintained list at /subprocessors).
Timeline
There is no committed audit date yet. We intend to close the operational gaps above — most urgently the request-logging fix and automated scanning noted on /security — before formally engaging an auditor. We'll update this page when a Type I observation period is scheduled.
Tooling
Infrastructure runs entirely on AWS-managed services (Lambda, CloudFront, S3, SES, ACM, CloudWatch) rather than self-managed servers, which keeps the control surface small and mostly inherited from AWS's own SOC 2 / ISO 27001 attestations for the underlying platform. Application-level controls (IAM scoping, patch cadence, dependency hygiene) are ours to build out and document.
VPC / self-hosted deployment
For customers who need document content to never leave their own network, a self-hosted or VPC-deployed variant of the extraction service is on the roadmap — the engine (Tika + Tesseract on Lambda-compatible runtimes) is already isolated enough to package this way. There's no shipped self-host artifact yet; if this is a blocker for your deal, tell us via /contact and we'll factor it into prioritization.
Stop parsing. Start shipping.
Create an account and get an API key in minutes — the free Hobby plan needs no card.
Get started →