Security

Evidence controls at every trust boundary.

Our launch architecture separates products, rechecks tenant authorization on the server, constrains provider access, and fails closed when evidence cannot be verified.

Architecture staged · customer processing disabled

No customer accounts, uploads, payments, or processing are enabled in the current marketing-only deployment.

01

Identity and tenancy

Verified-email WorkOS AuthKit, mandatory TOTP, server-side Convex membership checks, opaque IDs, generic cross-tenant not-found responses, and role-scoped transactions.

02

Private storage

Separate encrypted S3 buckets per product, customer/job-scoped keys, 15-minute single-object uploads, five-minute authorized downloads, and immediate access revocation on deletion.

03

Document safety

MIME and magic-byte agreement, malformed/encrypted/macro/archive rejection, Office-container bomb checks, malware scanning, immutable originals, exact duplicate hashes, and processing budgets.

04

OCR and models

Textract output is directed into customer-controlled encrypted storage. Claude Sonnet is pinned in Bedrock us-east-1 with zero-data-retention mode; unsupported model configuration fails closed.

05

Evidence verification

Citations are checked for product/tenant/job ownership, page, bounds, exact quote, derivability, field policy, confidence, contradictions, and unsupported negative answers.

06

Audit and telemetry

Immutable, content-safe audit events. Operational events contain opaque IDs, timing, provider status, cost, and error classes—never filenames, document contents, prompts, answers, or quotes.

07

Retention and deletion

7, 30, or 90-day retention; 30 days by default after completion. Access is revoked immediately and active/backup copies purge within eight days.

08

Billing

Stripe-hosted checkout and customer portal. Raw card data never enters the platform. Signed, replay-safe webhooks update subscription access idempotently.

Report a security concern

Do not include document contents or customer data. Send a concise description to support@certdraft.com.