SOC 2 is a roadmap item, not a badge we're wearing.

txtfetch is not SOC 2 certified today. Here's the honest scope of what that would take, and what we already do while we get there.

not certified today

txtfetch has not completed a SOC 2 Type II audit. Anyone telling you otherwise about a pre-launch product should be treated with suspicion — we'd rather say "not yet" than imply a badge we haven't earned.

Planned scope

The intended scope is a SOC 2 Type II report covering the Security and Availability Trust Services Criteria for the extraction API and its supporting AWS infrastructure. Confidentiality would extend naturally from the no-content-retention posture described at /security.

Gaps between today and an audit-ready state

  • Formal risk assessment and control documentation across the Trust Services Criteria (security, availability, confidentiality).
  • Automated dependency and runtime vulnerability scanning wired into CI (currently a manual process — see /security).
  • Independent third-party audit of controls over a defined observation period.
  • Formal vendor-management and sub-processor review process (today: a maintained list at /subprocessors).

Timeline

There is no committed audit date yet. We intend to close the operational gaps above — most urgently the request-logging fix and automated scanning noted on /security — before formally engaging an auditor. We'll update this page when a Type I observation period is scheduled.

Tooling

Infrastructure runs entirely on AWS-managed services (Lambda, CloudFront, S3, SES, ACM, CloudWatch) rather than self-managed servers, which keeps the control surface small and mostly inherited from AWS's own SOC 2 / ISO 27001 attestations for the underlying platform. Application-level controls (IAM scoping, patch cadence, dependency hygiene) are ours to build out and document.

VPC / self-hosted deployment

For customers who need document content to never leave their own network, a self-hosted or VPC-deployed variant of the extraction service is on the roadmap — the engine (Tika + Tesseract on Lambda-compatible runtimes) is already isolated enough to package this way. There's no shipped self-host artifact yet; if this is a blocker for your deal, tell us via /contact and we'll factor it into prioritization.

Stop parsing. Start shipping.

Create an account and get an API key in minutes — the free Hobby plan needs no card.

Get started →