Login
Security · Encryption · Compliance

Trust Center

Transparency is the foundation of trust. Here's exactly how Coventract protects your data, secures your contracts, and maintains enterprise-grade reliability.

Checking…

Security Measures

Multi-layered protection at every level

Authentication

Email/password + Google OAuth via Firebase Auth. Optional multi-factor authentication (MFA) for all accounts.

Role-Based Access Control

Granular roles: Freelancer, Small Business, Enterprise, Lawyer, Admin. Resources are scoped per user and team.

Rate Limiting

AI operations limited to 10 requests/min per IP. API routes protected against brute-force via server-side guards.

Audit Logging

Every create, edit, sign, and AI action is immutably recorded with user ID, IP address, and timestamp.

DDoS Protection

Google Cloud infrastructure provides automatic DDoS mitigation and global anycast routing.

Content Security Policy

Strict CSP headers, HSTS enforcement, and X-Frame-Options set to prevent clickjacking and XSS attacks.

Encryption

Your data is encrypted end-to-end

In-Transit Encryption

All traffic is encrypted using TLS 1.3 — the latest standard. No data is transmitted over unencrypted connections.

At-Rest Encryption

Firebase Firestore and Cloud Storage encrypt all data at rest using AES-256 managed by Google Cloud KMS.

Key Management

Encryption keys are managed by Google Cloud Key Management Service (KMS) with automatic rotation policies.

Password Hashing

User passwords are hashed using bcrypt via Firebase Auth — plaintext passwords are never stored.

End-to-End Encrypted Contract Storage

Contract content, signatures, and attachments are encrypted both in transit and at rest using industry-standard AES-256 encryption.

Data Storage

Enterprise-grade infrastructure powered by Google Cloud

Primary Database

Google Firebase Firestore — a globally distributed, serverless NoSQL database with automatic scaling.

File Storage

Firebase Cloud Storage for contract attachments, signatures, and media. Regional redundancy by default.

Automated Backups

Daily automated point-in-time backups retained for 30 days. Export to Google Cloud Storage for audit compliance.

Data Residency

Primary data hosted in Google Cloud us-central1 with global CDN for static assets via Firebase Hosting.

Data Retention

Contract versions retained for up to 20 snapshots per contract. Audit logs retained for 2 years. Accounts deleted on request.

Data Isolation

Multi-tenant data isolation enforced at the database level via Firestore Security Rules — users cannot access other tenants' data.

Compliance

Built to meet enterprise and regulatory standards

GDPR

Data protection rights for EU residents. Right to access, delete, and port your data.

SOC 2

Security, availability, and confidentiality controls audited by Google Cloud.

ISO 27001

Information security management system standard certified via GCP infrastructure.

CCPA

California Consumer Privacy Act compliance. Opt-out of data sale available.

Right to Erasure

Users can request full account and data deletion at any time from Account Settings.

Privacy Policy

Comprehensive privacy policy outlining data collection, usage, and rights.

Cookie Policy

Minimal cookie usage — authentication session tokens only. No third-party ad tracking.

System Uptime & Reliability

Real-time platform health monitoring

Checking…

99.9%

Target SLA

Monthly uptime target

Serverless

Architecture

Firebase + Next.js Edge

Global

CDN Regions

Google Cloud CDN

Status updates every 30 seconds. For incident reports, visit our support page.

Questions about security?

Our team is happy to provide detailed security documentation, conduct security reviews, or sign custom DPAs for enterprise customers.