Security
Your company documents,
protected.
DocuTrackr is built privacy-first. We track the dates that matter — not your sensitive paperwork. Here is exactly how.
On-device scanning
When you snap a photo of a document, the text is read on your device using local OCR. The image never has to leave the browser to extract a few fields (number, dates, type). No document image ever touches our servers.
Encryption at rest
The fields we store are encrypted with AES-256-GCM under a per-organization key. Even our own team cannot read them in the clear. Keys are never stored alongside the data they protect.
Encrypted in transit (TLS 1.3)
Every connection between your browser and DocuTrackr — including the API, dashboard, and webhooks — is protected by TLS 1.3 with HSTS enforced. There is no plain-HTTP fallback.
We keep dates, not documents
DocuTrackr exists to remind you before a license, permit, or work permit lapses. We only need the expiry date and a label — not the full document. We don't build a vault of your company's confidential paperwork.
Role-based access control
Each organization's data is fully isolated. Team members only see documents for their own company. Access is scoped by role: Owner, Admin, or Member — with owners able to add, suspend, or remove members at any time.
Passcode & session protection
Sensitive actions (viewing document details, exporting data) require re-authentication via a personal passcode. Sessions are tied to verified devices; removing a team member immediately invalidates all their active sessions.
Tamper-evident audit log
Every action — document added, member invited, permission changed, data exported — is written to an append-only audit log visible to org owners. Entries cannot be edited or deleted.
Infrastructure & data residency
DocuTrackr runs on Convex Cloud (US region, AWS us-east-1). Data is replicated across multiple availability zones. Backups are taken continuously with point-in-time recovery. We do not store data on shared or customer-managed infrastructure.
No third-party data sharing
We do not sell, rent, or share your data with advertisers or data brokers. The only sub-processors we use are: Convex (database), Resend (transactional email), and Stripe (billing). Each is bound by a data processing agreement.
GDPR & privacy compliance
DocuTrackr is designed for GDPR compliance. You can export all your data at any time from Settings. Account deletion removes all personally identifiable data within 30 days. We act as a data processor for your organization; you remain the controller.
Questions?
Email hello@docutrackr.app — we are happy to walk through our security posture in detail, provide a security questionnaire response, or arrange a technical review call.