---
title: Security
description: What is in place today, and what is not.
---

# Security

What is in place today, and what is not.

## Today

Data in transit travels over TLS. Each workspace's data is separated from every other's by row-level rules in the database itself, enforced on every table, not only in the application. People sign in with a password or an emailed code, and a workspace owner can require two-step sign-in with an authenticator app. Sessions can be listed and ended. Signed documents are sealed with a digital signature. Secrets such as mail passwords are stored encrypted. Responses carry modern security headers. Requests are rate-limited, and signing links are single-purpose tokens that are never kept in the address bar after load.

## Backups

The database is backed up every day to a separate location, and once a week a backup is restored into a scratch database to prove it works.

## Test mode

Test mode sends mail only to the sender, stamps every page TEST, and is never counted or billed.

## Not yet

No outside audit or certification has been done and none is claimed. There is no bug-bounty programme. Encryption of stored documents depends on the storage service's own settings and is not separately claimed.

## Report a problem

Write to security@docustay.app with what you found. We read every report.

## How separation between workspaces works

Each workspace's rows in the database carry a workspace identifier, and the database itself refuses to return another workspace's rows. The rule is enforced on every table, so a mistake in application code cannot show one customer another's data. The same idea applies to documents and signed copies: they are fetched through the workspace you are signed in to.

## Signing links

A signing link carries a single-purpose token. After the page loads, the token is removed from the address bar so it is not left in history, screenshots or shared screens. Links expire, and a link for one document cannot be used for another.

## Keys and secrets

API keys are scoped, so a key can be limited to what a job needs, and can be revoked at once. Mail passwords and similar secrets are stored encrypted. Webhook deliveries are signed so your server can tell they came from Docustay.

## If something goes wrong

The database is backed up every day, and once a week a backup is restored into a scratch database to prove it works. If you find a security problem, write to security@docustay.app with what you saw; every report is read.

## Keep reading

- [Privacy](/trust/privacy)
- [Legal validity](/trust/legal-validity)
- [Proof and the signed copy](/product/proof)
- [Docs: authentication](/docs/authentication)
- [Developers](/developers)
