Security

Private paperwork. Public marketing. Not the reverse.

This page describes controls that exist in the product. It does not claim certifications we have not published.

Workspace isolation

Application data is stored per organization. Database access for tenant data uses row-level security so one company cannot read another company's records through the Data API.

Public customer links

Share links store a SHA-256 hash of the token, not the raw token. Quote, invoice, and receipt pages load a snapshot through the Contactor Docs server rather than exposing the database to the browser.

Customer documents are not indexed

Authenticated app routes, admin routes, and public customer quote, invoice, and receipt token URLs send noindex instructions and are disallowed in robots.txt. Those pages are for the people you sent them to.

Uploads

Files are checked for extension, MIME type, magic bytes, and size before they are stored. That applies to logos, notes, and jobsite photos.

Issued documents

Signed versions are stored as issued. The customer should see the same numbers you sent, not a draft that changed under them.

Secrets and keys

Service role keys and model provider keys stay on the server. Browser clients do not receive them.

Payments

When online payment is enabled, card data is handled by Stripe. Contactor Docs does not store card numbers. Receipts are generated from recorded payments, not from a typed-in card form on our servers.

Transport and framing

Production is served over HTTPS. Responses include standard security headers such as frame deny, nosniff, and a strict-origin referrer policy.

Questions about a specific control, data export, or incident report can go to the contact page. We will not invent a compliance badge to answer them.

Start with a photo of the job.

Create your company workspace, apply your branding, and send the first quote from what you already wrote down on site.