SOC 2 is a roadmap item, not a badge we're wearing.

txtfetch is not SOC 2 certified today. Here's the honest scope of what that would take, and what we already do while we get there.

not certified today

txtfetch has not completed a SOC 2 Type II audit. Be suspicious of anyone who tells you otherwise about a pre-launch product. We'd rather say "not yet" than imply a badge we haven't earned.

Planned scope

The intended scope is a SOC 2 Type II report covering the Security and Availability Trust Services Criteria. It would cover the extraction API and its supporting AWS infrastructure. Confidentiality would extend naturally from the no-content-retention posture described at /security.

Gaps between today and an audit-ready state

  • Formal risk assessment and control documentation across the Trust Services Criteria (security, availability, confidentiality).
  • Automated dependency and runtime vulnerability scanning wired into CI. Today it's a manual process; see /security.
  • Independent third-party audit of controls over a defined observation period.
  • Formal vendor-management and sub-processor review process (today: a maintained list at /subprocessors).

Timeline

There is no committed audit date yet. We intend to close the operational gaps above before formally engaging an auditor, most urgently the request-logging fix and automated scanning noted on /security. We'll update this page when a Type I observation period is scheduled.

Tooling

Infrastructure runs entirely on AWS-managed services: Lambda, CloudFront, S3, SES, ACM, and CloudWatch. There are no self-managed servers. That keeps the control surface small, and most of it is inherited from AWS's own SOC 2 and ISO 27001 attestations for the underlying platform. Application-level controls (IAM scoping, patch cadence, dependency hygiene) are ours to build out and document.

VPC / self-hosted deployment

Some customers need document content to never leave their own network. For them, a self-hosted or VPC-deployed variant of the extraction service is on the roadmap. The engine (Tika and Tesseract on Lambda-compatible runtimes) is already isolated enough to package this way. There's no shipped self-host artifact yet; if this is a blocker for your deal, tell us via /contact and we'll factor it into prioritization.

Stop parsing. Start shipping.

Create an account and get an API key in minutes. The free Hobby plan needs no card.

Get started →