Built on a foundation you can trust.

Security isn't a feature we bolted on — it's the architecture we started with. Your files, your clients' data, and every payment are protected at every layer.

1

Upload

Your files go straight into private, encrypted storage.

2

Deliver

Your client gets their own secure environment — no public links.

3

Verify

Payment is confirmed server-side before anything unlocks.

4

Release

Files unlock, and every access is written to the audit trail.

Payments handled by Stripe

We never see your client's card details. Every payment flows through Stripe — a PCI-DSS Level 1 certified processor trusted by millions of businesses. Your bank info stays between your client and Stripe.

  • TODO — detail point
  • TODO — detail point

Encrypted at rest, private by default

Files are stored on Cloudflare R2, which applies AES-256 server-side encryption to every object by default. Storage is fully private — no URL gives direct access without passing through our authentication layer first.

  • TODO — detail point
  • TODO — detail point

Server-side payment verification

File access is never granted on the client side. Stripe sends a signed webhook directly to our server — we verify the HMAC signature, confirm the payment, and only then unlock the files. A faked browser redirect gets you nothing.

  • TODO — detail point
  • TODO — detail point

Instant access revocation

Every file request is checked against live permissions in real time. Unlike signed URLs that can't be recalled, revoking a client's access takes effect on their very next request — no expiry window to wait out, no loopholes.

  • TODO — detail point
  • TODO — detail point

Complete client isolation

Each client lives in their own private space. Row-Level Security enforced at the database means one client can never see another's files, invoices, or project data — even if application code had a bug.

  • TODO — detail point
  • TODO — detail point

Full audit trail

Every view, download attempt, and access event is logged with a timestamp, IP address, and user identity. You always know exactly who accessed what and when — giving you a clear record if a dispute ever arises.

  • TODO — detail point
  • TODO — detail point

Where your data lives

TODO — hosting locations, sub-processors, and how Docman handles GDPR requests.

Found a vulnerability?

We take reports seriously and respond quickly. Reach us at mail@docman.online and we'll get back to you.