Filevine

Filevine Platform Trust Center

Filevine Core is the all-in-one legal case management platform built for law firms of every size. It centralizes matter management, document storage, deadline tracking, client communication, and team collaboration into a single, configurable workspace. Vinesign is Filevine's native eSignature solution, purpose-built for legal workflows. It allows attorneys and staff to send, sign, and manage legally binding documents directly within the Filevine platform, no third-party tool required.
⌘K

Compliance Programs

See All (1)
The ongoing systems Filevine maintains to stay secure and prove it—covering the policies, processes, and tools that ensure regulatory and security requirements are consistently met.

Controls

See All (230)
Controls are the specific safeguards or security requirements put in place to reduce risk and protect systems, data, and operations.

ADS-01

Pass
Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and machine-readable formats, including at least: • Direct link to the FedRAMP Marketplace for the offering • Service Model • Deployment Model • Business Category • UEI Number • Contact Information • Overall Service Description • Detailed list of specific services and their impact levels (see FRR-ADS-03) • Summary of customer responsibilities and secure configuration guidance • Process for accessing information in the trust center (if applicable) • Availability status and recent disruptions for the trust center (if applicable) • Customer support information for the trust center (if applicable)

ADS-02

Pass
Providers MUST use automation to ensure information remains consistent between human-readable and machine-readable formats when authorization data is provided in both formats; Providers SHOULD generate human-readable and machine-readable data from the same source at the same time OR generate human-readable formats directly from machine-readable data.

ADS-03

Pass
Providers MUST share a detailed list of specific services and their impact levels that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP authorization without requesting access to underlying authorization data.

Interconnections

See All (4)
A direct and specific system-to-system connection between Filevine Cloud, the Cloud Service Offering (CSO), and another external systems or services.

Slack

System Notifications

Azure Commmercial Cloud

Hosts the system environment

Google Drive

System Documentation

Deliverables

See All (8)
The evidence packages that demonstrate Filevine has implemented required controls and is maintaining compliance.

Coalfire - FedRAMP 20x Assessment Letter

Official third-party assessment validation letter from Coalfire confirming our FedRAMP 20x compliance and security control effectiveness.

Filevine - FedRAMP 20x Moderate Package

FedRAMP 20x Moderate authorization package including KSI implementations, evidence, and third-party assessment.

Vinesign FedRAMP Secure Configuration Guide.pdf

Vinesign FedRAMP Secure Configuration guide PDF form