Trust Center
Transparency is the foundation of trust. Here's exactly how Coventract protects your data, secures your contracts, and maintains enterprise-grade reliability.
Checking…
Security Measures
Multi-layered protection at every level
Authentication
Email/password + Google OAuth via Firebase Auth. Optional multi-factor authentication (MFA) for all accounts.
Role-Based Access Control
Granular roles: Freelancer, Small Business, Enterprise, Lawyer, Admin. Resources are scoped per user and team.
Rate Limiting
AI operations limited to 10 requests/min per IP. API routes protected against brute-force via server-side guards.
Audit Logging
Every create, edit, sign, and AI action is immutably recorded with user ID, IP address, and timestamp.
DDoS Protection
Google Cloud infrastructure provides automatic DDoS mitigation and global anycast routing.
Content Security Policy
Strict CSP headers, HSTS enforcement, and X-Frame-Options set to prevent clickjacking and XSS attacks.
Encryption
Your data is encrypted end-to-end
In-Transit Encryption
All traffic is encrypted using TLS 1.3 — the latest standard. No data is transmitted over unencrypted connections.
At-Rest Encryption
Firebase Firestore and Cloud Storage encrypt all data at rest using AES-256 managed by Google Cloud KMS.
Key Management
Encryption keys are managed by Google Cloud Key Management Service (KMS) with automatic rotation policies.
Password Hashing
User passwords are hashed using bcrypt via Firebase Auth — plaintext passwords are never stored.
End-to-End Encrypted Contract Storage
Contract content, signatures, and attachments are encrypted both in transit and at rest using industry-standard AES-256 encryption.
Data Storage
Enterprise-grade infrastructure powered by Google Cloud
Primary Database
Google Firebase Firestore — a globally distributed, serverless NoSQL database with automatic scaling.
File Storage
Firebase Cloud Storage for contract attachments, signatures, and media. Regional redundancy by default.
Automated Backups
Daily automated point-in-time backups retained for 30 days. Export to Google Cloud Storage for audit compliance.
Data Residency
Primary data hosted in Google Cloud us-central1 with global CDN for static assets via Firebase Hosting.
Data Retention
Contract versions retained for up to 20 snapshots per contract. Audit logs retained for 2 years. Accounts deleted on request.
Data Isolation
Multi-tenant data isolation enforced at the database level via Firestore Security Rules — users cannot access other tenants' data.
Compliance
Built to meet enterprise and regulatory standards
GDPR
Data protection rights for EU residents. Right to access, delete, and port your data.
SOC 2
Security, availability, and confidentiality controls audited by Google Cloud.
ISO 27001
Information security management system standard certified via GCP infrastructure.
CCPA
California Consumer Privacy Act compliance. Opt-out of data sale available.
Right to Erasure
Users can request full account and data deletion at any time from Account Settings.
Privacy Policy
Comprehensive privacy policy outlining data collection, usage, and rights.
Cookie Policy
Minimal cookie usage — authentication session tokens only. No third-party ad tracking.
System Uptime & Reliability
Real-time platform health monitoring
Checking…
99.9%
Target SLA
Monthly uptime target
Serverless
Architecture
Firebase + Next.js Edge
Global
CDN Regions
Google Cloud CDN
Status updates every 30 seconds. For incident reports, visit our support page.
Questions about security?
Our team is happy to provide detailed security documentation, conduct security reviews, or sign custom DPAs for enterprise customers.