Document Requests
This page lists the compliance, audit, and business documents Files.com provides on request, along with how to obtain each. It also covers the documents we do not provide and the reasons why.
Documents Available on Request
The following documents are available to customers and qualified prospects. Some require a signed Non-Disclosure Agreement (NDA) before release.
All compliance documentation Files.com makes available to customers is published in the Files.com Trust Center. Our public SOC 2 Type II Framework page covers the scope of the SOC 2 Type II audit, our audit history, and the current and upcoming report dates. The Accessing the Report section at the bottom of that page explains how to obtain the requested documents through the Files.com Trust Center.
| Document | What it is | NDA required | How to request |
|---|---|---|---|
| SOC 2 Type II report | Full audit report covering the Security, Availability, and Confidentiality Trust Services Criteria, performed annually by Kirkpatrick Price. | Access to the Files.com Trust Center requires a signed NDA. | Trust Center |
| SOC 2 Bridge Letter | Letter covering the gap between the most recent SOC 2 audit period and the current date. | Access to the Files.com Trust Center requires a signed NDA. | Trust Center |
| Completed CAIQ v4 | Files.com's responses to the Cloud Security Alliance Consensus Assessments Initiative Questionnaire. | Access to the Files.com Trust Center requires a signed NDA. | Trust Center |
| PCI AOC (Attestation of Compliance) | Most recent PCI DSS Level 2 AOC. | Access to the Files.com Trust Center requires a signed NDA. | Trust Center |
| Penetration Test Completion Letters | Formal confirmation that third-party penetration testing was performed. | Access to the Files.com Trust Center requires a signed NDA. | Trust Center |
| VPAT (Voluntary Product Accessibility Template) | Independently audited report documenting the Files.com web application's conformance to WCAG 2.1 Level AA, criterion by criterion. | Access to the Files.com Trust Center requires a signed NDA. | Trust Center. See the WCAG / ADA section. |
| W-9 Form | Files.com (Action Verb LLC) IRS Form W-9 for tax and vendor onboarding. | Access to the Files.com Trust Center requires a signed NDA. | Trust Center |
| Financial Audit Completion Letter | Letter from Grant Thornton LLP attesting to completion of our annual financial audit. | No | Contact your Account Executive or Customer Support. |
| Data Processing Agreement (DPA) | Pre-written, pre-approved DPA covering GDPR-compliant processing terms, including Standard Contractual Clauses (SCCs) for cross-border transfers. | No | Contact your Account Executive or Customer Support. See the GDPR page. |
| Business Associate Agreement (BAA) | Pre-written, pre-approved BAA for HIPAA. Available only on Enterprise plans. | No | Contact your Account Executive or Customer Support. See the HIPAA page. |
| DORA Addendum | Contractual addendum supporting EU Digital Operational Resilience Act obligations. Available to qualified customers. | No | Contact your Account Executive or Customer Support. See the DORA page. |
Documents We Do Not Provide
The following documents are sometimes requested in security reviews but Files.com does not release.
- Certificates of Insurance (COI). Files.com maintains industry-standard insurance coverage. We do not issue COIs to customers.
- AWS audit reports. Files.com reviews AWS's SOC 2 report annually as part of our vendor management program, but AWS NDA terms prevent us from sharing it directly. AWS publishes its compliance documentation through AWS Artifact.
- Product roadmap. Detailed product plans are shared only with members of the Files.com Customer Advisory Board under NDA.
- Live customer references. Not provided as a standard practice. For prospective engagements with annual contract value above $100,000, references may be arranged on a case-by-case basis. For other prospects, see verified customer reviews on G2 and Gartner Peer Insights.
Frameworks Not Listed Here
If your organization requires a document for a compliance framework not listed on this page, contact your Account Executive or Customer Support. We will assess whether the request can be supported through existing documentation or a custom response.