Built on a foundation you can trust.
Security isn't a feature we bolted on — it's the architecture we started with. Your files, your clients' data, and every payment are protected at every layer.
Upload
Your files go straight into private, encrypted storage.
Deliver
Your client gets their own secure environment — no public links.
Verify
Payment is confirmed server-side before anything unlocks.
Release
Files unlock, and every access is written to the audit trail.
Payments handled by Stripe
We never see your client's card details. Every payment flows through Stripe — a PCI-DSS Level 1 certified processor trusted by millions of businesses. Your bank info stays between your client and Stripe.
- TODO — detail point
- TODO — detail point
Encrypted at rest, private by default
Files are stored on Cloudflare R2, which applies AES-256 server-side encryption to every object by default. Storage is fully private — no URL gives direct access without passing through our authentication layer first.
- TODO — detail point
- TODO — detail point
Server-side payment verification
File access is never granted on the client side. Stripe sends a signed webhook directly to our server — we verify the HMAC signature, confirm the payment, and only then unlock the files. A faked browser redirect gets you nothing.
- TODO — detail point
- TODO — detail point
Instant access revocation
Every file request is checked against live permissions in real time. Unlike signed URLs that can't be recalled, revoking a client's access takes effect on their very next request — no expiry window to wait out, no loopholes.
- TODO — detail point
- TODO — detail point
Complete client isolation
Each client lives in their own private space. Row-Level Security enforced at the database means one client can never see another's files, invoices, or project data — even if application code had a bug.
- TODO — detail point
- TODO — detail point
Full audit trail
Every view, download attempt, and access event is logged with a timestamp, IP address, and user identity. You always know exactly who accessed what and when — giving you a clear record if a dispute ever arises.
- TODO — detail point
- TODO — detail point
Where your data lives
TODO — hosting locations, sub-processors, and how Docman handles GDPR requests.
Found a vulnerability?
We take reports seriously and respond quickly. Reach us at mail@docman.online and we'll get back to you.