Skip to main content
Display
Security

How I keep your data safe

Last updated September 26, 2026

Your project details, files and messages are private to you, the people you invite, and me. Here's what protects them.

Signing in

  • Accounts are by invitation only; nobody can sign themselves up.
  • Passwords must be at least 12 characters and are checked against lists of passwords exposed in known data leaks.
  • Passwords are stored using Argon2id, a one-way scramble, so no one can read them, not even me.
  • On a device you haven't trusted, a 6-digit code is emailed to you before you can get in.
  • You can add an authenticator app or a passkey for even stronger protection.
  • Repeated wrong passwords or codes are slowed down and blocked.
  • You can see where you're signed in and sign out other devices from your Account page.

Your information

  • Everything travels over an encrypted connection (HTTPS with HSTS), and data is encrypted where it's stored.
  • Each business can only ever see its own requests, files and messages. This is checked on every page and every download.
  • Files are kept in private storage and can only be downloaded by signed-in people from your business, and by me.
  • Uploads are checked to make sure they are what they claim to be.
  • Card payments happen on Stripe's secure page. Card details never touch this site.
  • The database is backed up every night, and restoring from a backup is tested.

Keeping watch

  • Sign-ins, invitations, changes and downloads are recorded in a security log that can't be edited.
  • Software updates are checked automatically every week, and every change is reviewed and tested before it goes live.
  • The site sends strict browser security headers, including a Content Security Policy.

The companies involved

The portal is hosted by Vercel, with the database on Neon, email through Resend and payments through Stripe. Each of these providers holds an independent SOC 2 Type II report. The portal itself follows the same SOC 2 controls (access control, encryption, logging, change management and incident response), but it hasn't had its own SOC 2 audit.

If something goes wrong

If there's ever a problem that affects your information, I'll look into it straight away, stop it, and tell you what happened and what I'm doing about it, within 72 hours of finding out.

Report a security problem

Found a weakness? Please email support@thultz.dev with “Security” in the subject. Please don't access other people's data or disrupt the service while testing. I'll reply quickly and credit you if you'd like. See also security.txt.