Last updated: August 7, 2026

Filevine Security Addendum

This Security Addendum is part of the Agreement between Filevine, Inc. (“Filevine”) and the customer identified in the applicable Sales Order (“Subscriber”) and describes the security measures Filevine maintains to protect Subscriber’s Data. Capitalized terms not defined in this Security Addendum have the meaning given in the Subscription Agreement or the DPA. To the extent of a conflict between this Security Addendum and the DPA regarding data protection matters, the DPA controls; to the extent of a conflict regarding technical or organizational security measures, this Security Addendum controls. Updates to this Security Addendum are governed by Section 1.2 of the Subscription Agreement.

  1. Filevine Audits and Certifications
    1. Filevine’s information security program is assessed by independent third-party auditors on at least an annual basis through a SOC 2 Type II audit and an assessment against the ISO/IEC control frameworks. These frameworks currently include ISO 27001, ISO 27701, ISO 27017, ISO 27018 and ISO 42001, but may change from time to time. Filevine is aligned with NIST 800-53 Rev 5.* with respect to FedRAMP 20X Low & Moderate certifications for specific Filevine products.
    2. Where applicable to the Services purchased by Subscriber, Filevine’s security program has also been assessed against the HIPAA Privacy & Security Rule and the FBI’s Criminal Justice Information Services (CJIS) Security Policy 5.9.5*.
    3. Filevine will make available a summary of its most recent audit report as described in Section 10 (Customer Audit Rights).
    4. If Filevine discontinues a certification or audit described in this Section 1, Filevine will endeavor to adopt an equivalent, industry-recognized framework in its place.
  2. Data Hosting Location
    1. Subscriber’s Data is stored and processed in data centers located in the United States, unless otherwise specified in the applicable Sales Order.
    2. Subscriber may request that its Data be stored in a specific geographic region. Filevine will use commercially reasonable efforts to accommodate such a request where supported by Filevine’s underlying cloud infrastructure and consistent with applicable law.
  3. Encryption
    1. Filevine encrypts Subscriber’s Data at rest using AES-256* encryption, and in transit over public or untrusted networks using TLS 1.2*.
    2. Filevine utilizes an encryption key management system (KMS) and rotates encryption keys as needed, typically on an annual basis, and logically separates encryption key management systems from Subscriber’s Data.
  4. System and Network Security
    1. Access to systems containing Subscriber’s Data requires unique credentials issued consistent with the principle of least privilege, a secure connection, multi-factor authentication, and passwords meeting minimum length and complexity requirements.
    2. Filevine personnel will not access Subscriber’s Data except (a) to provide or support the Services, or (b) to comply with applicable law or a binding legal order.
    3. Filevine personnel access Filevine’s environment using company-managed devices employing encryption, endpoint detection and response tooling.
    4. Filevine uses threat detection tooling to monitor for malicious code but has no obligation to monitor Subscriber’s Data for malicious code.
    5. Filevine engages an independent third party to conduct penetration testing of the Services at least annually and maintains an ongoing vulnerability management program, including a public bug bounty program. Summaries of penetration test results are available as described in Section 10 (Customer Audit Rights).
    6. Filevine monitors public vulnerability databases and uses commercially reasonable efforts to remediate identified vulnerabilities within a risk-appropriate timeframe based on severity and exploitability.
    7. Filevine conducts annual web application security assessments, including testing for vulnerability classes identified by the Open Web Application Security Project (OWASP Top 10), such as cross-site scripting, cross-site request forgery, and injection vulnerabilities.
  5. Administrative and Personnel Controls
    1. Filevine personnel receive security awareness training at onboarding and at least annually thereafter, covering individual security and privacy responsibilities, Filevine’s information security policies, phishing and social engineering awareness, and device and credential hygiene.
    2. Filevine trains software developers on secure development practices at least annually, including prevention of common vulnerability classes such as injection, cross-site scripting, and authentication or authorization bypass.
    3. Filevine personnel sign confidentiality agreements and are required to report suspected security incidents.
    4. To the extent permitted by applicable law, Filevine performs background screening — including identity verification, right-to-work verification, and a criminal history check — for personnel with access to Subscriber’s Data. For applicable staff, additional screening, such as that required by CJIS, FedRAMP, or government agency obligations, is performed.
    5. Access for departing personnel is removed from systems containing Subscriber’s Data within one (1) business day and from all other systems within three (3) business days. Filevine reviews personnel access privileges at least quarterly.
    6. Filevine monitors external threat intelligence sources, such as FBI or CISA advisories, and prioritizes remediation of critical and high-severity vulnerabilities consistent with Section 4.6.
  6. Vendor and Sub-processor Security
    1. Before engaging a material Sub-processor to process Subscriber’s Data, Filevine assesses the Sub-processor’s security practices and requires by written agreement that the Sub-processor maintain security measures designed to be no less protective than those described in this Security Addendum, to the extent applicable to the services it provides.
    2. Filevine maintains a current list of Sub-processors at https://www.filevine.com/subprocessors/.
    3. Filevine will exercise commercially reasonable care in the selection and oversight of its Sub-processors’ acts and omissions only to the extent Filevine would be responsible if it performed the applicable services directly.
  7. Physical Data Center Controls
    1. The Services are hosted on infrastructure provided by leading cloud infrastructure providers, independently audited under SOC 2 Type II and ISO 27001 (or an equivalent framework), with controls that include: controlled facility ingress; visitor identification and sign-in; access-controlled server areas subject to periodic review; monitoring, alarm, and video surveillance coverage; fire detection and suppression systems; backup power and redundancy; and environmental controls.
    2. Filevine does not host or store Subscriber’s Data at its corporate offices.
  8. Security Incident Notification and Response
    1. If Filevine confirms a breach of security leading to the destruction, loss, alteration, or unauthorized disclosure of, or access to, Subscriber’s Data (a “Security Breach”), Filevine will notify Subscriber without undue delay, at the contact identified in the applicable Sales Order.
    2. Filevine will promptly investigate, contain, and remediate the Security Breach, and will endeavor to preserve logs relevant to the Security Breach for at least one (1) year.
    3. Filevine will provide Subscriber with timely information regarding the nature and consequences of the Security Breach, the status of its investigation, and a point of contact for further information, and will share information about remediation measures once the investigation concludes. Subscriber acknowledges that because Filevine personnel may have limited visibility into the content of Subscriber’s Data, Filevine’s ability to describe the specific Data affected may be limited.
    4. Communications made in connection with a Security Breach will not be construed as an admission of fault or liability by Filevine.
    5. Except where the Security Breach arises from Subscriber’s instructions, negligence, or breach of the Agreement, Filevine will bear its own reasonable costs of investigating and remediating the Security Breach.
  9. Audit Logging
    1. Filevine maintains audit logs reasonably sufficient to monitor, investigate, and report unauthorized or inappropriate system activity, with actions of individual users traceable to those users.
    2. Audit logs are retained for at least one (1) year and are encrypted and protected against unauthorized modification or deletion.
  10. Customer Audit Rights
    1. Upon written request, and at no additional cost to Subscriber, Filevine will provide Subscriber (or its appropriately qualified third-party representative, the “Auditor”) with Filevine’s most recent SOC 2 Type II report. Filevine may provide evidence of Filevine’s ISO 27001 status, a summary of Filevine’s most recent penetration test, and/or a data flow diagram for the applicable Filevine Service. Any third-party Auditor must execute a confidentiality agreement with Filevine before receiving this documentation, and Filevine may reasonably object to an Auditor it believes is not suitably qualified, in which case Subscriber will
      designate an alternative Auditor.
    2. Subscriber may submit a security questionnaire (not to exceed fifty (50) questions in any twelve (12) month period) or a request for updated security documentation, and Filevine will respond within six (6) weeks at no cost to Subscriber.
    3. If the documentation described in Section 10.1 is unavailable or Subscriber reasonably requires further verification, Filevine will permit Subscriber (or its Auditor) to audit Filevine’s compliance with this Security Addendum upon at least thirty (30) days’ written notice, subject to reasonable scheduling and confidentiality protections.
  11. Subscriber Responsibilities
    1. Subscriber is responsible for ensuring it is authorized to submit its Data to the Services and that its use complies with applicable law.
    2. Subscriber is responsible for managing and securing its own means of accessing the Services, including Logon Credentials, private API keys, personal access tokens (PATs), and shared or guest links. Credentials may not be shared, and Subscriber must
      promptly report any suspected unauthorized access and confirmed breach events.
    3. Subscriber is responsible for keeping its own IT systems — including the browser used to access the Services — up to date and appropriately patched, and for enabling available security features such as multi-factor authentication for its Authorized Users.
      1. Shared Responsibility Model:
        1. Filevine
          Responsibilities
          1. AWS infrastructure security
          2. Encryption in transit and at rest
          3. Application-level access controls
          4. Centralized monitoring and incident response
          5. Platform availability and backups
        2. Subscriber
          Responsibilities
          1. Identity provider security
          2. User provisioning and deprovisioning
          3. MFA enforcement
          4. Tenant configuration
          5. Tenant activity monitoring
          6. Endpoint and network security
          7. Regulatory compliance and data governance
    4. Filevine disclaims liability for Security Breaches or other security incidents to the extent arising from Subscriber’s failure to satisfy its obligations under this Section 11.
  12. Business Continuity and Disaster Recovery
    1. Filevine maintains business continuity and disaster recovery plans addressing the key personnel, systems, and processes needed to restore the Services following a significant disruption. These plans are reviewed and tested regularly.
  13. Data Retention and Destruction
    1. Following termination or expiration of the Subscription Agreement, Filevine is not obligated to retain Subscriber’s Data for more than thirty (30) days, subject to Subscriber’s timely election under the Subscription Agreement to have such Data destroyed or returned. Upon written request, Filevine will provide written certification of deletion or destruction of Subscriber’s Data.

Where a version, revision, standard, or protocol in this Security Addendum is marked with an asterisk, Filevine may satisfy the applicable commitment using the stated item or any successor or higher version, or a substantially equivalent or more protective standard, that Filevine adopts from time to time.

 

 

 

Last updated: August 7, 2026