docEvault

Security

How we protect your data · docEvault LLC · support@docevault.com

Every document uploaded through docEvault is encrypted in transit and at rest using the same standards trusted by banks, healthcare systems, and government agencies. This page explains exactly how we protect your data and your clients' information.

Encryption at Rest

  • All uploaded documents and files are stored using AES-256 encryption via Cloudflare R2
  • AES-256 is the same encryption standard used by the US government for classified information
  • Files are encrypted before being written to disk and decrypted only when accessed through an authenticated request
  • Database contents (contacts, requests, metadata) are encrypted at the infrastructure level by Railway

Encryption in Transit

  • All data transmitted between your browser and docEvault servers is protected by TLS 1.3
  • HTTPS is enforced on every connection — unencrypted HTTP is never accepted
  • Strict Transport Security (HSTS) headers prevent protocol downgrade attacks
  • All connections between our backend and Cloudflare R2 are encrypted

Secure File Access

  • Uploaded documents are never accessible via a public URL
  • Every file download requires a time-limited presigned URL generated by our authenticated backend
  • Presigned URLs expire automatically — a link shared outside the portal cannot be used to access files
  • File access is logged with timestamps and IP addresses for every download

Access Logging & Audit Trail

  • Every portal access is logged with timestamp, IP address, and user agent
  • Every document upload, approval, rejection, and N/A marking is recorded in a detailed activity feed
  • Every reminder sent is logged with channel (email/SMS), timestamp, and whether it was manual or automatic
  • Attorneys can view the complete activity history for each request at any time
  • Contacts can view their own portal access history at the bottom of every portal page

Account Security

  • Passwords are hashed using bcrypt with a cost factor of 12 — plain text passwords are never stored
  • Single-session enforcement per seat: signing in on a new device immediately invalidates the previous session
  • JSON Web Tokens (JWTs) are signed with a 384-bit secret key and expire after 7 days
  • Session validity is checked on every authenticated API request — a displaced session is rejected immediately
  • Role-based access control: admin-only features are enforced at both the frontend and backend API level

Infrastructure Security

  • Backend hosted on Railway with network isolation and automatic TLS certificate management
  • Frontend served globally via Netlify CDN with automatic HTTPS
  • File storage on Cloudflare R2 - files never leave Cloudflare globally distributed infrastructure
  • Database (PostgreSQL) hosted on Railway with no public internet access - only accessible from our backend
  • Environment variables (API keys, secrets) are stored as encrypted environment secrets, never in code

API & Integration Security

  • Zapier integration API keys are stored as SHA-256 hashes — the plain key is shown only once at creation
  • Webhook deliveries are signed with HMAC-SHA256 so recipients can verify the payload is genuine
  • Rate limiting on all API endpoints: 300 requests per 15 minutes globally, stricter limits on auth endpoints
  • SMS and Zapier features are enforced at the API level by plan — plan restrictions cannot be bypassed by modifying frontend code
  • Request bodies are sanitized to strip dangerous fields (role, orgId, plan) before any route handler processes them

How We Compare to Email

  • Email is the most common alternative to docEvault — and significantly less secure
  • Email attachments are transmitted and stored in plain text on mail servers you do not control
  • There is no audit trail of who opened or downloaded a file sent by email
  • Accidentally replying-all or forwarding an email exposes documents to unintended recipients
  • The docEvault contact portal eliminates all of these risks — documents never touch email

Responsible Disclosure

If you discover a security vulnerability in docEvault, please report it to us at support@docevault.com with "Security Vulnerability" in the subject line. We take all reports seriously and will respond within 48 hours. Please do not publicly disclose the vulnerability until we have had the opportunity to address it.

Questions

If you have questions about our security practices or need documentation for a compliance review, contact us at support@docevault.com. We are happy to provide additional detail for enterprise procurement processes.

docEvault

© 2026 docEvault LLC. All rights reserved.