This Security Addendum is part of the
Agreement between Filevine, Inc. (“Filevine”) and the customer
identified in the applicable Sales Order (“Subscriber”) and describes
the security measures Filevine maintains to protect Subscriber’s Data.
Capitalized terms not defined in this Security Addendum have the meaning given
in the Subscription Agreement or the DPA. To the extent of a conflict between
this Security Addendum and the DPA regarding data protection matters, the DPA
controls; to the extent of a conflict regarding technical or organizational
security measures, this Security Addendum controls. Updates to this Security
Addendum are governed by Section 1.2 of the Subscription Agreement.
1. Filevine Audits and Certifications
1.1.
Filevine’s
information security program is assessed by independent third-party auditors on
at least an annual basis through a SOC 2 Type II audit and an assessment
against the ISO/IEC control frameworks. These frameworks currently include ISO
27001, ISO 27701, ISO 27017, ISO 27018 and ISO 42001, but may change from time
to time. Filevine is aligned with NIST 800-53 Rev 5.* with respect to FedRAMP
20X Low & Moderate certifications for specific Filevine products.
1.2.
Where
applicable to the Services purchased by Subscriber, Filevine’s security program
has also been assessed against the HIPAA Privacy & Security Rule and the
FBI’s Criminal Justice Information Services (CJIS) Security Policy 5.9.5*.
1.3.
Filevine
will make available a summary of its most recent audit report as described in
Section 10 (Customer Audit Rights).
1.4.
If
Filevine discontinues a certification or audit described in this Section 1,
Filevine will endeavor to adopt an equivalent, industry-recognized framework in
its place.
2. Data Hosting Location
2.1.
Subscriber’s
Data is stored and processed in data centers located in the United States,
unless otherwise specified in the applicable Sales Order.
2.2.
Subscriber
may request that its Data be stored in a specific geographic region. Filevine
will use commercially reasonable efforts to accommodate such a request where
supported by Filevine’s underlying cloud infrastructure and consistent with
applicable law.
3. Encryption
3.1.
Filevine
encrypts Subscriber’s Data at rest using AES-256* encryption, and in transit
over public or untrusted networks using TLS 1.2*.
3.2.
Filevine
utilizes an encryption key management system (KMS) and rotates encryption keys as
needed, typically on an annual basis, and logically separates encryption key
management systems from Subscriber’s Data.
4. System and Network Security
4.1.
Access
to systems containing Subscriber’s Data requires unique credentials issued
consistent with the principle of least privilege, a secure connection,
multi-factor authentication, and passwords meeting minimum length and
complexity requirements.
4.2.
Filevine
personnel will not access Subscriber’s Data except (a) to provide or support
the Services, or (b) to comply with applicable law or a binding legal order.
4.3.
Filevine
personnel access Filevine’s environment using company-managed devices employing
encryption, endpoint detection and response tooling.
4.4.
Filevine
uses threat detection tooling to monitor for malicious code but has no
obligation to monitor Subscriber’s Data for malicious code.
4.5.
Filevine
engages an independent third party to conduct penetration testing of the Services
at least annually and maintains an ongoing vulnerability management program,
including a public bug bounty program. Summaries of penetration test results
are available as described in Section 10 (Customer Audit Rights).
4.6.
Filevine
monitors public vulnerability databases and uses commercially reasonable
efforts to remediate identified vulnerabilities within a risk-appropriate
timeframe based on severity and exploitability.
4.7.
Filevine
conducts annual web application security assessments, including testing for
vulnerability classes identified by the Open Web Application Security Project
(OWASP Top 10), such as cross-site scripting, cross-site request forgery, and
injection vulnerabilities.
5. Administrative and Personnel Controls
5.1.
Filevine
personnel receive security awareness training at onboarding and at least
annually thereafter, covering individual security and privacy responsibilities,
Filevine’s information security policies, phishing and social engineering
awareness, and device and credential hygiene.
5.2.
Filevine
trains software developers on secure development practices at least annually,
including prevention of common vulnerability classes such as injection,
cross-site scripting, and authentication or authorization bypass.
5.3.
Filevine
personnel sign confidentiality agreements and are required to report suspected
security incidents.
5.4.
To
the extent permitted by applicable law, Filevine performs background screening
— including identity verification, right-to-work verification, and a criminal
history check — for personnel with access to Subscriber’s Data. For applicable
staff, additional screening, such as that required by CJIS, FedRAMP, or
government agency obligations, is performed.
5.5.
Access
for departing personnel is removed from systems containing Subscriber’s Data
within one (1) business day and from all other systems within three (3)
business days. Filevine reviews personnel access privileges at least quarterly.
5.6.
Filevine
monitors external threat intelligence sources, such as FBI or CISA advisories,
and prioritizes remediation of critical and high-severity vulnerabilities
consistent with Section 4.6.
6. Vendor and Sub-processor Security
6.1.
Before
engaging a material Sub-processor to process Subscriber’s Data, Filevine
assesses the Sub-processor’s security practices and requires by written
agreement that the Sub-processor maintain security measures designed to be no
less protective than those described in this Security Addendum, to the extent
applicable to the services it provides.
6.2.
Filevine
maintains a current list of Sub-processors at https://www.filevine.com/subprocessors/.
6.3.
Filevine
will exercise commercially reasonable care in the selection and oversight of
its Sub-processors’ acts and omissions only to the extent Filevine would be
responsible if it performed the applicable services directly.
7. Physical Data Center Controls
7.1.
The
Services are hosted on infrastructure provided by leading cloud infrastructure providers,
independently audited under SOC 2 Type II and ISO 27001 (or an equivalent
framework), with controls that include: controlled facility ingress; visitor
identification and sign-in; access-controlled server areas subject to periodic
review; monitoring, alarm, and video surveillance coverage; fire detection and
suppression systems; backup power and redundancy; and environmental controls.
7.2.
Filevine
does not host or store Subscriber’s Data at its corporate offices.
8. Security Incident Notification and Response
8.1.
If
Filevine confirms a breach of security leading to the destruction, loss,
alteration, or unauthorized disclosure of, or access to, Subscriber’s Data (a “Security
Breach”), Filevine will notify Subscriber without undue delay, at the
contact identified in the applicable Sales Order.
8.2.
Filevine
will promptly investigate, contain, and remediate the Security Breach, and will
endeavor to preserve logs relevant to the Security Breach for at least one (1)
year.
8.3.
Filevine
will provide Subscriber with timely information regarding the nature and
consequences of the Security Breach, the status of its investigation, and a
point of contact for further information, and will share information about
remediation measures once the investigation concludes. Subscriber acknowledges
that because Filevine personnel may have limited visibility into the content of
Subscriber’s Data, Filevine’s ability to describe the specific Data affected
may be limited.
8.4.
Communications
made in connection with a Security Breach will not be construed as an admission
of fault or liability by Filevine.
8.5.
Except
where the Security Breach arises from Subscriber’s instructions, negligence, or
breach of the Agreement, Filevine will bear its own reasonable costs of
investigating and remediating the Security Breach.
9. Audit Logging
9.1.
Filevine
maintains audit logs reasonably sufficient to monitor, investigate, and report
unauthorized or inappropriate system activity, with actions of individual users
traceable to those users.
9.2.
Audit
logs are retained for at least one (1) year and are encrypted and protected
against unauthorized modification or deletion.
10. Customer Audit Rights
10.1.
Upon
written request, and at no additional cost to Subscriber, Filevine will provide
Subscriber (or its appropriately qualified third-party representative, the “Auditor”)
with Filevine’s most recent SOC 2 Type II report. Filevine may provide evidence
of Filevine’s ISO 27001 status, a summary of Filevine’s most recent penetration
test, and/or a data flow diagram for the applicable Filevine Service. Any
third-party Auditor must execute a confidentiality agreement with Filevine
before receiving this documentation, and Filevine may reasonably object to an
Auditor it believes is not suitably qualified, in which case Subscriber will
designate an alternative Auditor.
10.2.
Subscriber
may submit a security questionnaire (not to exceed fifty (50) questions in any
twelve (12) month period) or a request for updated security documentation, and
Filevine will respond within six (6) weeks at no cost to Subscriber.
10.3.
If
the documentation described in Section 10.1 is unavailable or Subscriber
reasonably requires further verification, Filevine will permit Subscriber (or
its Auditor) to audit Filevine’s compliance with this Security Addendum upon at
least thirty (30) days’ written notice, subject to reasonable scheduling and
confidentiality protections.
11. Subscriber Responsibilities
11.1.
Subscriber
is responsible for ensuring it is authorized to submit its Data to the Services
and that its use complies with applicable law.
11.2.
Subscriber
is responsible for managing and securing its own means of accessing the Services,
including Logon Credentials, private API keys, personal access tokens (PATs),
and shared or guest links. Credentials may not be shared, and Subscriber must
promptly report any suspected unauthorized access and confirmed breach events.
11.3.
Subscriber
is responsible for keeping its own IT systems — including the browser used to
access the Services — up to date and appropriately patched, and for enabling
available security features such as multi-factor authentication for its
Authorized Users.
11.3.1.
Shared
Responsibility Model:
Filevine
Responsibilities
- AWS infrastructure
security - Encryption in transit
and at rest - Application-level
access controls - Centralized monitoring
and incident response - Platform availability
and backups
Subscriber
Responsibilities
- Identity provider
security - User provisioning and
deprovisioning - MFA enforcement
- Tenant configuration
- Tenant activity
monitoring - Endpoint and network
security - Regulatory compliance
and data governance
11.4.
Filevine
disclaims liability for Security Breaches or other security incidents to the
extent arising from Subscriber’s failure to satisfy its obligations under this
Section 11.
12. Business Continuity and Disaster Recovery
12.1.
Filevine
maintains business continuity and disaster recovery plans addressing the key
personnel, systems, and processes needed to restore the Services following a
significant disruption. These plans are reviewed and tested regularly.
13. Data Retention and Destruction
13.1.
Following
termination or expiration of the Subscription Agreement, Filevine is not
obligated to retain Subscriber’s Data for more than thirty (30) days, subject
to Subscriber’s timely election under the Subscription Agreement to have such
Data destroyed or returned. Upon written request, Filevine will provide written
certification of deletion or destruction of Subscriber’s Data.
*
Where a version, revision,
standard, or protocol in this Security Addendum is marked with an asterisk,
Filevine may satisfy the applicable commitment using the stated item or any
successor or higher version, or a substantially equivalent or more protective
standard, that Filevine adopts from time to time.
Last updated: July 30, 2026