Security

Your contracts stay your contracts

Bank-grade encryption, role-based access, audit logs, and a strict no-training AI pledge — built for confidential business documents.

Encryption in transit

All upload, download, and API traffic is HTTPS-only with TLS 1.2+. HSTS is enabled site-wide.

Encryption at rest

Documents are stored in Cloudflare R2 with AES-256 encryption at rest. Database is Postgres on Railway (EU West) with encrypted volumes.

Access controls

Role-based access (owner, admin, member) on every team. Server actions verify session + team membership before reading any document.

Audit logs

Every document upload, review run, role change, and deletion is recorded with actor, IP, user agent, and timestamp. Retained for the life of the account.

Retention + deletion

Documents are retained for as long as your team needs them. Soft-delete in the dashboard hides them; hard-delete on request purges from R2 + DB within 30 days.

No training on your data

We never use your contracts to train models. Inference requests carry team and user metadata for traceability only, and the model provider is contractually barred from training on them. Your contracts are your contracts.

Sub-processors

A small list of best-in-class providers we use to deliver the service. All third-party sub-processors maintain SOC 2 Type II or ISO 27001 certifications.

  • Anthropic
    AI inference
  • Cloudflare R2
    Object storage
  • Railway
    Compute + Postgres (EU West)
  • Flitt
    Card payment processing
  • Resend
    Transactional email
  • Sentry / PostHog
    Errors + product analytics

Need a security questionnaire or DPA?

All accounts get encrypted processing and zero data retention for training. Scale and Pro tiers include signed DPA and SOC 2 questionnaire assistance.