Your account, your region
DocuSwift is provisioned with CloudFormation into the AWS account and region you choose, e.g. ap-south-1 (Mumbai) with DR in ap-south-2 (Hyderabad). HabileLabs has no standing access to your environment.
Regulated institutions trust DocuSwift with KYC packets, loan files and customer records because the controls are built in — not bolted on. The platform runs in your AWS account, encrypts everything, logs every action immutably and gives your compliance team the evidence regulators ask for.
AWS Qualified Software
DocuSwift has completed the AWS Foundational Technical Review, an independent assessment of security, reliability and operational excellence against the AWS Well-Architected Framework.
Each control is implemented in the product and verifiable in your own account.
DocuSwift is provisioned with CloudFormation into the AWS account and region you choose, e.g. ap-south-1 (Mumbai) with DR in ap-south-2 (Hyderabad). HabileLabs has no standing access to your environment.
TLS 1.2+ in transit (CloudFront and API Gateway enforce a TLS floor). Amazon S3 server-side encryption with AWS KMS keys you control at rest; DynamoDB tables encrypted by default.
Amazon Cognito user pools with TOTP multi-factor authentication, lockout after repeated failures, password policies, 30-minute idle timeout and single sign-on with Microsoft Entra ID.
Permissions by user, group, source and folder. Read, write, approve and admin tiers. Time-boxed auditor access and periodic access-review campaigns.
Every login, view, download, upload, edit, approval, share and signature is logged with actor, object, result and IP. Logs are system-generated and cannot be edited or deleted.
Audit batches are chained and verified continuously. Export evidence packs and a signed attestation PDF for regulators and internal audit.
Default and per-category retention policies, statutory templates for Indian banking, cold-storage archival at end of life and legal holds that block deletion during disputes.
Built-in probes check region, encryption, TLS floor, MFA policy, audit retention, evidence chain, SIEM export and share policy — and alert on drift.
Stream audit events to Splunk, Sentinel, QRadar or any SIEM so document activity is correlated with the rest of your security estate.
Mask Aadhaar numbers and other PII at upload through FinHub's masking API, and redact regions in the viewer before sharing. Only essential metadata is retained.
Pre-signed, expiring download URLs; share policies that restrict external domains, maximum link lifetime and PII exposure; public links disabled by default.
Amazon S3 versioning and 99.999999999% durability, AWS Backup policies, cross-region replication and an active-active option proven at 99.99% uptime.
DocuSwift probes its own deployment and shows the result on one screen: region, encryption at rest, TLS floor, MFA policy, audit retention, evidence-chain integrity, SIEM destination and share policy. Export a signed attestation PDF whenever an auditor asks.


Filter by actor type, action, result and date; search by email; export logs or a complete evidence pack. Batches are hash-chained, verified on a schedule and surfaced as “chain intact” — or not.
Documents, keys, logs and the bill stay in your account. HabileLabs operates nothing inside it.
Branch & HQ staff
Web console · SSO
Auditors
Read-only, time-boxed
LOS · LMS · CRM
API & webhooks
Amazon CloudFront
Console on your domain
Amazon Cognito
MFA · Entra ID SSO
Amazon API Gateway
REST + WebSocket
AWS Lambda
Business logic
Amazon S3
Documents · KMS encrypted
Amazon DynamoDB
Metadata · audit index
Amazon Textract
OCR
Amazon Bedrock
Summaries · chat
Amazon SES
Notifications
AWS Backup
Policy-based backups
Cross-region DR
Active-active option
Amazon CloudWatch
Metrics · alarms
A clear split between AWS, DocuSwift and your team.
| Area | AWS | DocuSwift | Your organisation |
|---|---|---|---|
| Physical & network infrastructure | ✓ | — | — |
| Application security & secure SDLC | — | ✓ | — |
| Encryption configuration & KMS keys | Managed service | Enabled by default | Own the keys |
| User lifecycle, roles & access reviews | — | Tooling | Policy & operation |
| Retention schedules & legal holds | — | Tooling & templates | Policy decisions |
| Monitoring, alarms & SIEM integration | CloudWatch | Metrics & export | SOC operation |
| Upgrades & patches | Managed runtimes | Release pipeline | Approve updates |
Share your vendor assessment or RFP and our team will respond with architecture diagrams, control mappings and references.
Or email info@habilelabs.io · Monday to Friday, 10:00–19:00 IST (excluding public holidays)