Security
These principles guide how SafeDocs is being built — not certifications or completed audits, which we don't have yet.
Our privacy-first philosophy
Privacy by Design
Privacy and access control are treated as requirements from the start of development, not features added afterward. Every design decision considers who should — and shouldn't — be able to see a document.
Secure Storage
Protecting documents with modern security practices for storage and transmission is a core requirement of the build. As SafeDocs matures, we'll share more detail about the specific safeguards in place.
Controlled Sharing
Access is intended to be explicit rather than automatic: you'll choose exactly who can see a document, and set an expiration for that access.
Audit History
SafeDocs will keep a visible record of document access, so activity is never hidden from the person it belongs to.
Security foundations
The safeguards SafeDocs is being designed around.
These are design goals, not verified or currently available product controls:
- AES-256 encryption at rest
- TLS encryption in transit
- Fine-grained role-based access
- Secure sharing with expiration controls
- Immutable audit trails
- Continuous backups
- Privacy-first architecture
SafeDocs does not yet have compliance certifications or completed external security audits. These safeguards will be validated and documented as the platform matures.
Data Ownership
You own your documents. SafeDocs is being designed so you always retain ownership and control of what you upload — we don't claim rights to your content, and access controls are designed to ensure only you, and whoever you explicitly grant access to, can view it.
Threat Model
At a high level, SafeDocs is being designed to protect against:
- Unauthorized access to your documents
- Tampering with document history
- Accidental oversharing
This is a summary of our thinking, not a completed security audit. We'll publish more detail as the architecture matures.
Responsible disclosure
If you believe you've found a security issue with this website or with SafeDocs, we'd like to know. Please email hello@safedocs.io with the subject line "Security report" and as much detail as you can share.
SafeDocs is a small, early-stage team. We don't yet have a formal bug bounty program, dedicated security inbox, or PGP key — we'll add those as the company grows. What we can commit to now: we'll read every report and respond.
Security roadmap
SafeDocs keeps a single, up-to-date product roadmap rather than a separate one for security specifically — audit trails and access control are part of that same plan.
View the full roadmap →