How we protect your data · docEvault LLC · support@docevault.com
Every document uploaded through docEvault is encrypted in transit and at rest using the same standards trusted by banks, healthcare systems, and government agencies. This page explains exactly how we protect your data and your clients' information.
Encryption at Rest
All uploaded documents and files are stored using AES-256 encryption via Cloudflare R2
AES-256 is the same encryption standard used by the US government for classified information
Files are encrypted before being written to disk and decrypted only when accessed through an authenticated request
Database contents (contacts, requests, metadata) are encrypted at the infrastructure level by Railway
Encryption in Transit
All data transmitted between your browser and docEvault servers is protected by TLS 1.3
HTTPS is enforced on every connection — unencrypted HTTP is never accepted
Strict Transport Security (HSTS) headers prevent protocol downgrade attacks
All connections between our backend and Cloudflare R2 are encrypted
Secure File Access
Uploaded documents are never accessible via a public URL
Every file download requires a time-limited presigned URL generated by our authenticated backend
Presigned URLs expire automatically — a link shared outside the portal cannot be used to access files
File access is logged with timestamps and IP addresses for every download
Access Logging & Audit Trail
Every portal access is logged with timestamp, IP address, and user agent
Every document upload, approval, rejection, and N/A marking is recorded in a detailed activity feed
Every reminder sent is logged with channel (email/SMS), timestamp, and whether it was manual or automatic
Attorneys can view the complete activity history for each request at any time
Contacts can view their own portal access history at the bottom of every portal page
Account Security
Passwords are hashed using bcrypt with a cost factor of 12 — plain text passwords are never stored
Single-session enforcement per seat: signing in on a new device immediately invalidates the previous session
JSON Web Tokens (JWTs) are signed with a 384-bit secret key and expire after 7 days
Session validity is checked on every authenticated API request — a displaced session is rejected immediately
Role-based access control: admin-only features are enforced at both the frontend and backend API level
Infrastructure Security
Backend hosted on Railway with network isolation and automatic TLS certificate management
Frontend served globally via Netlify CDN with automatic HTTPS
File storage on Cloudflare R2 - files never leave Cloudflare globally distributed infrastructure
Database (PostgreSQL) hosted on Railway with no public internet access - only accessible from our backend
Environment variables (API keys, secrets) are stored as encrypted environment secrets, never in code
API & Integration Security
Zapier integration API keys are stored as SHA-256 hashes — the plain key is shown only once at creation
Webhook deliveries are signed with HMAC-SHA256 so recipients can verify the payload is genuine
Rate limiting on all API endpoints: 300 requests per 15 minutes globally, stricter limits on auth endpoints
SMS and Zapier features are enforced at the API level by plan — plan restrictions cannot be bypassed by modifying frontend code
Request bodies are sanitized to strip dangerous fields (role, orgId, plan) before any route handler processes them
How We Compare to Email
Email is the most common alternative to docEvault — and significantly less secure
Email attachments are transmitted and stored in plain text on mail servers you do not control
There is no audit trail of who opened or downloaded a file sent by email
Accidentally replying-all or forwarding an email exposes documents to unintended recipients
The docEvault contact portal eliminates all of these risks — documents never touch email
Responsible Disclosure
If you discover a security vulnerability in docEvault, please report it to us at support@docevault.com with "Security Vulnerability" in the subject line. We take all reports seriously and will respond within 48 hours. Please do not publicly disclose the vulnerability until we have had the opportunity to address it.
Questions
If you have questions about our security practices or need documentation for a compliance review, contact us at support@docevault.com. We are happy to provide additional detail for enterprise procurement processes.