Trust
Security
What is in place today, and what is not.
Today
Data in transit travels over TLS. Each workspace's data is separated from every other's by row-level rules in the database itself, enforced on every table, not only in the application. People sign in with a password or an emailed code, and a workspace owner can require two-step sign-in with an authenticator app. Sessions can be listed and ended. Signed documents are sealed with a digital signature. Secrets such as mail passwords are stored encrypted. Responses carry modern security headers. Requests are rate-limited, and signing links are single-purpose tokens that are never kept in the address bar after load.
Backups
The database is backed up every day to a separate location, and once a week a backup is restored into a scratch database to prove it works.
Test mode
Test mode sends mail only to the sender, stamps every page TEST, and is never counted or billed.
Not yet
No outside audit or certification has been done and none is claimed. There is no bug-bounty programme. Encryption of stored documents depends on the storage service's own settings and is not separately claimed.
Report a problem
Write to security@docustay.app with what you found. We read every report.
How separation between workspaces works
Each workspace's rows in the database carry a workspace identifier, and the database itself refuses to return another workspace's rows. The rule is enforced on every table, so a mistake in application code cannot show one customer another's data. The same idea applies to documents and signed copies: they are fetched through the workspace you are signed in to.
Signing links
A signing link carries a single-purpose token. After the page loads, the token is removed from the address bar so it is not left in history, screenshots or shared screens. Links expire, and a link for one document cannot be used for another.
Keys and secrets
API keys are scoped, so a key can be limited to what a job needs, and can be revoked at once. Mail passwords and similar secrets are stored encrypted. Webhook deliveries are signed so your server can tell they came from Docustay.
If something goes wrong
The database is backed up every day, and once a week a backup is restored into a scratch database to prove it works. If you find a security problem, write to security@docustay.app with what you saw; every report is read.