> Source: https://txtfetch.com/compliance > Plain-text twin — every page on txtfetch.com has one. https://txtfetch.com/text --- # SOC 2 is a roadmap item, not a badge we're wearing. txtfetch is not SOC 2 certified today. Here's the honest scope of what that would take, and what we already do while we get there. not certified today txtfetch has not completed a SOC 2 Type II audit. Be suspicious of anyone who tells you otherwise about a pre-launch product. We'd rather say "not yet" than imply a badge we haven't earned. ## Planned scope The intended scope is a SOC 2 Type II report covering the Security and Availability Trust Services Criteria. It would cover the extraction API and its supporting AWS infrastructure. Confidentiality would extend naturally from the no-content-retention posture described at [/security](https://txtfetch.com/security). ## Gaps between today and an audit-ready state - Formal risk assessment and control documentation across the Trust Services Criteria (security, availability, confidentiality). - Automated dependency and runtime vulnerability scanning wired into CI. Today it's a manual process; see /security. - Independent third-party audit of controls over a defined observation period. - Formal vendor-management and sub-processor review process (today: a maintained list at /subprocessors). ## Timeline There is no committed audit date yet. We intend to close the operational gaps above before formally engaging an auditor, most urgently the request-logging fix and automated scanning noted on [/security](https://txtfetch.com/security). We'll update this page when a Type I observation period is scheduled. ## Tooling Infrastructure runs entirely on AWS-managed services: Lambda, CloudFront, S3, SES, ACM, and CloudWatch. There are no self-managed servers. That keeps the control surface small, and most of it is inherited from AWS's own SOC 2 and ISO 27001 attestations for the underlying platform. Application-level controls (IAM scoping, patch cadence, dependency hygiene) are ours to build out and document. ## VPC / self-hosted deployment Some customers need document content to never leave their own network. For them, a self-hosted or VPC-deployed variant of the extraction service is on the roadmap. The engine (Tika and Tesseract on Lambda-compatible runtimes) is already isolated enough to package this way. There's no shipped self-host artifact yet; if this is a blocker for your deal, tell us via [/contact](https://txtfetch.com/contact) and we'll factor it into prioritization. ## Stop parsing. Start shipping. Create an account and get an API key in minutes. The free Hobby plan needs no card. [Get started →](https://app.txtfetch.com/signup)