Product documentation

Guides for requests, templates, client portals, analytics, and security - everything your team needs to run document collection at scale.

Data Security

Your data and your clients' data is protected with enterprise-grade security measures. Infile takes security seriously, implementing multiple layers of protection to keep sensitive information safe.

Encryption

All data is encrypted at every stage:

  • In-Transit Encryption: All data transmitted between clients and Infile servers uses TLS 1.3 encryption, the latest and most secure protocol. This protects data as it travels across the internet.
  • At-Rest Encryption: All stored data, including documents and database records, is encrypted using AES-256 encryption. This military-grade encryption ensures data remains secure even if physical storage is compromised.
  • Secure File Storage: Uploaded files are stored in secure, redundant cloud storage with automatic backups. Files are distributed across multiple data centers for reliability.
  • Encryption Key Management: Encryption keys are managed separately from data and rotated regularly. Keys are never stored alongside the data they protect.

Access Controls

Strict access controls ensure only authorized users can view sensitive data:

  • Role-Based Permissions: Team members only access what they need based on their role. Admins can view and modify all data, while Members may only see assigned clients.
  • Two-Factor Authentication (2FA): Enable 2FA for an extra layer of account security. Requires a code from your phone in addition to your password when logging in.
  • Session Management: Automatic logout after periods of inactivity. Sessions are invalidated when you log out, preventing unauthorized access from shared devices.
  • IP Whitelisting: Restrict access to your account from specific IP addresses or ranges. Available on Enterprise plans for organizations with strict security policies.
  • Audit Logs: Comprehensive logs track all data access and changes. See who viewed, modified, or exported data, with timestamps and IP addresses. Logs are immutable and retained for compliance.
  • Single Sign-On (SSO): Integrate with your organization's identity provider (Okta, Azure AD, Google Workspace) for centralized access management. Available on Enterprise plans.

Data Retention & Deletion

Control how long data is kept and ensure secure deletion:

  • Configurable Retention: Set automatic deletion policies for old submissions (e.g., delete after 1 year, 3 years, or 7 years). Helps meet data minimization requirements.
  • Secure Deletion: When data is deleted, it's permanently removed from all systems including backups. Deletion is cryptographically verified and irreversible.
  • Export Before Deletion: Receive automatic reminders to export data before it's deleted. Ensures you have local copies for your records.
  • Right to Deletion: Clients can request deletion of their data at any time. You can process these requests with a single click, ensuring GDPR compliance.

Security Best Practice: Enable two-factor authentication for all team members, especially those with Admin or Manager roles. Regularly review audit logs for suspicious activity.

Collect docs effortlessly. Your clients will love it.

Join 200+ firms who cut document chaos down to zero - no email threads, no missed files.

No credit card required · Cancel anytime