Trust center
Everything your diligence file needs, in one request.
Most firms ask for the same eight documents. Rather than making you chase them one at a time, here is the whole set with what it covers and how to get it.
Documents
What we can send you.
- Under NDAUpdated March 2026
SOC 2 Type II report
Security, availability and confidentiality trust services criteria. Covers the zero-training control.
- Under NDAUpdated June 2026
Penetration test summary
Annual third-party application and infrastructure test. Executive summary and remediation status.
- Under NDAUpdated January 2026
ISO 27001 hosting attestation
Certification for the data centres hosting the US and India regions.
- Public Read now
Data Processing Addendum
Includes the contractual model-training exclusion, retention terms and breach notification obligations.
- Public Read now
Subprocessor list
Every third party that may process customer content, with purpose and location. 30-day notice before changes.
- Under NDAUpdated April 2026
ABA Model Rule 1.6 & 5.3 memo
How Docket Build maps to the confidentiality and supervisory duties, written for firm diligence files.
- Under NDAUpdated February 2026
Business continuity and DR plan
RTO, RPO, backup schedule and failover procedure across regions.
- Under NDAUpdated August 2026
Security questionnaire responses
Pre-completed CAIQ and a standard legal-vendor questionnaire, for firms whose corporate clients require them.
Typical turnaround: one business day once the NDA is executed.
Standing
Certifications and compliance posture.
SOC 2 Type II
Certified
Issued March 2026 · next observation window opens January 2027
ISO 27001
Hosting
Data centre certification held by our infrastructure provider
GDPR
Compliant
DPA with standard contractual clauses; EU representative appointed
CCPA / CPRA
Compliant
Service provider terms; no sale or sharing of personal information
US data residency
Available
Selectable at firm level; processing stays in region
India data residency
Available
Second region live since Q2 2026
Reporting a vulnerability
Responsible disclosure.
We publish an RFC 9116 security.txt and we respond to every report. Send findings to security@docketbuild.com. Acknowledgement within one business day, triage within three, and we will keep you updated until it is closed.
We do not currently run a paid bounty programme. We do credit reporters publicly with their permission, and we will never pursue legal action against good-faith research conducted within the scope in our security.txt.
Read security.txtIncident commitments
- Notification to affected firms
- Within 24 hours of confirmation
- Written incident report
- Within 5 business days
- Post-incident review
- Shared with any firm that requests it
- Status page updates
- Every 30 minutes during an active incident
- Regulatory notification support
- Assistance with firm obligations where applicable
Start free trial
Stop losing flat-fee profit to manual PDF formatting.
Upload one messy client folder. Get back an audit-ready, Bates-stamped exhibit packet with a two-tier index and a matched cover letter — in about three minutes.
14-day free production trial · no card · real matters · no watermark
Software for licensed attorneys. Not legal advice.