Skip to content
Security & compliance

Security-first by architecture, audit-ready by default

Regulated institutions trust DocuSwift with KYC packets, loan files and customer records because the controls are built in — not bolted on. The platform runs in your AWS account, encrypts everything, logs every action immutably and gives your compliance team the evidence regulators ask for.

AWS Qualified Software badge

AWS Qualified Software

DocuSwift has completed the AWS Foundational Technical Review, an independent assessment of security, reliability and operational excellence against the AWS Well-Architected Framework.

  • Data residency in Indian AWS regions
  • Controls aligned to DPDP Act 2023 obligations
  • Evidence for RBI / NHB / IRDAI IT governance reviews
  • Supports ISO 27001 and SOC 2 control programmes
Controls

Twelve controls your auditors will ask about

Each control is implemented in the product and verifiable in your own account.

Your account, your region

DocuSwift is provisioned with CloudFormation into the AWS account and region you choose, e.g. ap-south-1 (Mumbai) with DR in ap-south-2 (Hyderabad). HabileLabs has no standing access to your environment.

Encryption everywhere

TLS 1.2+ in transit (CloudFront and API Gateway enforce a TLS floor). Amazon S3 server-side encryption with AWS KMS keys you control at rest; DynamoDB tables encrypted by default.

Strong authentication

Amazon Cognito user pools with TOTP multi-factor authentication, lockout after repeated failures, password policies, 30-minute idle timeout and single sign-on with Microsoft Entra ID.

Least-privilege access

Permissions by user, group, source and folder. Read, write, approve and admin tiers. Time-boxed auditor access and periodic access-review campaigns.

Immutable audit trail

Every login, view, download, upload, edit, approval, share and signature is logged with actor, object, result and IP. Logs are system-generated and cannot be edited or deleted.

Hash-chained evidence archive

Audit batches are chained and verified continuously. Export evidence packs and a signed attestation PDF for regulators and internal audit.

Retention & legal holds

Default and per-category retention policies, statutory templates for Indian banking, cold-storage archival at end of life and legal holds that block deletion during disputes.

Compliance posture

Built-in probes check region, encryption, TLS floor, MFA policy, audit retention, evidence chain, SIEM export and share policy — and alert on drift.

SIEM export

Stream audit events to Splunk, Sentinel, QRadar or any SIEM so document activity is correlated with the rest of your security estate.

PII & Aadhaar masking

Mask Aadhaar numbers and other PII at upload through FinHub's masking API, and redact regions in the viewer before sharing. Only essential metadata is retained.

Controlled sharing

Pre-signed, expiring download URLs; share policies that restrict external domains, maximum link lifetime and PII exposure; public links disabled by default.

Backup & disaster recovery

Amazon S3 versioning and 99.999999999% durability, AWS Backup policies, cross-region replication and an active-active option proven at 99.99% uptime.

Continuous assurance

Compliance posture you can export

DocuSwift probes its own deployment and shows the result on one screen: region, encryption at rest, TLS floor, MFA policy, audit retention, evidence-chain integrity, SIEM destination and share policy. Export a signed attestation PDF whenever an auditor asks.

DocuSwift compliance posture dashboard with control cards and an Export Attestation PDF button
DocuSwift audit log showing tamper-evident archive status and recorded events
Audit trail

Every action, recorded and tamper-evident

Filter by actor type, action, result and date; search by email; export logs or a complete evidence pack. Batches are hash-chained, verified on a schedule and surfaced as “chain intact” — or not.

Architecture

Everything runs inside your AWS boundary

Documents, keys, logs and the bill stay in your account. HabileLabs operates nothing inside it.

Branch & HQ staff

Web console · SSO

Auditors

Read-only, time-boxed

LOS · LMS · CRM

API & webhooks

Your AWS account · your region (e.g. ap-south-1)

Amazon CloudFront

Console on your domain

Amazon Cognito

MFA · Entra ID SSO

Amazon API Gateway

REST + WebSocket

AWS Lambda

Business logic

Amazon S3

Documents · KMS encrypted

Amazon DynamoDB

Metadata · audit index

Amazon Textract

OCR

Amazon Bedrock

Summaries · chat

Amazon SES

Notifications

AWS Backup

Policy-based backups

Cross-region DR

Active-active option

Amazon CloudWatch

Metrics · alarms

DocuSwift is provisioned with AWS CloudFormation. Documents, keys, logs and the bill stay in your account; HabileLabs operates nothing inside it.
Shared responsibility

Who does what

A clear split between AWS, DocuSwift and your team.

AreaAWSDocuSwiftYour organisation
Physical & network infrastructure✓——
Application security & secure SDLC—✓—
Encryption configuration & KMS keysManaged serviceEnabled by defaultOwn the keys
User lifecycle, roles & access reviews—ToolingPolicy & operation
Retention schedules & legal holds—Tooling & templatesPolicy decisions
Monitoring, alarms & SIEM integrationCloudWatchMetrics & exportSOC operation
Upgrades & patchesManaged runtimesRelease pipelineApprove updates
Security FAQ

Questions from security and compliance teams

Where are our documents stored?
In your own AWS account and region. DocuSwift is provisioned with AWS CloudFormation into the AWS account you nominate (for example Mumbai ap-south-1 with disaster recovery in Hyderabad ap-south-2). Documents sit in Amazon S3 buckets you own, encrypted at rest; HabileLabs has no access to your account or your documents.
How secure is DocuSwift?
DocuSwift follows a security-first architecture: encryption in transit (TLS 1.2+) and at rest (Amazon S3 server-side encryption with AWS KMS), Amazon Cognito authentication with TOTP multi-factor authentication and Microsoft Entra ID single sign-on, role-based access control by user, group, source and folder, pre-signed expiring download URLs, idle-session timeouts and immutable audit logs. The product has passed the AWS Foundational Technical Review (FTR).
What do the audit logs capture and can they be altered?
Audit logs record uploads, views, downloads, edits, version changes, approvals, share events and signatures with user, timestamp and document identifiers. Logs are system-generated and immutable — they cannot be edited or deleted by users or administrators. You can filter by date range, export them, and stream them to a SIEM.
Does DocuSwift help with DPDP Act and RBI expectations?
DocuSwift gives you the technical controls those frameworks expect: data residency in an Indian AWS region, encryption, least-privilege access, PII and Aadhaar masking, retention rules, legal holds, access reviews and tamper-resistant audit trails. Your compliance team remains responsible for policies and processes; DocuSwift supplies the evidence.
How long does it take to go live?
A standard deployment is provisioned in your AWS account in under a day. Most customers complete configuration — sources, metadata schemas, roles and approval flows — within one to two weeks, followed by migration of existing documents. Large migrations (tens of terabytes) are phased and run in parallel with day-to-day use.
Do we need to manage any servers?
No. DocuSwift is built entirely on serverless AWS services — AWS Lambda, Amazon API Gateway, Amazon DynamoDB, Amazon S3 and Amazon Cognito — which scale automatically and carry no idle cost. There are no instances to patch and no capacity to plan.
What about backup and disaster recovery?
Amazon S3 provides 99.999999999% durability, AWS Backup enforces policy-based backups, and DocuSwift supports cross-region replication and an active-active deployment across two regions. Aavas Financiers runs this design across Mumbai and Hyderabad and reports 99.99% uptime.
Get started

Need a security questionnaire completed?

Share your vendor assessment or RFP and our team will respond with architecture diagrams, control mappings and references.

Or email info@habilelabs.io · Monday to Friday, 10:00–19:00 IST (excluding public holidays)