Security

Your documents contain sensitive information. Here's exactly how we protect them.

Encryption everywhere

All documents are encrypted at rest with AES-256 and in transit with TLS 1.3. Encryption keys are managed separately from the data they protect.

Secure infrastructure

Documents are stored on Cloudflare R2 · a globally distributed, enterprise-grade object storage built on Cloudflare's network. Authentication is handled by Supabase, which is SOC 2 Type II certified.

We don't read your documents

Document content is never accessed by Doxufy employees. Our systems process documents only to render them for signing · we have no interest in their contents.

Signed URL access

Documents are never publicly accessible. Every download or preview uses a short-lived signed URL that expires within the hour. There are no guessable file paths.

Legal audit trail

Every action on a document · viewed, signed, declined, voided · is logged with a timestamp, IP address, and browser fingerprint. This trail is immutable and forms part of the document record.

Vulnerability disclosure

If you discover a security vulnerability, please email [email protected]. We will acknowledge your report within 48 hours and keep you informed as we resolve it. We do not take legal action against good-faith security researchers.

Report a vulnerability

Security researchers who responsibly disclose vulnerabilities help make Doxufy safer for everyone. Please email [email protected] with details of the issue. Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.