Security

Security overview

Example content — pending review by the security/compliance team.

⚠️ This page describes intended practices, not audited or certified claims. Do not publish specific certifications (SOC 2, ISO 27001, HIPAA, etc.) here until they are actually obtained and verifiable.

Encryption

[Example] Documents are encrypted in transit (TLS) and at rest. Access to stored documents is limited to services that need it to perform redaction.

Access control

[Example] Team access is scoped per project with role-based permissions. Authentication is handled by Clerk, including support for modern authentication flows.

Data retention

[Example] Uploaded documents and redaction results are retained only as long as needed to provide the service, and can be deleted by the account owner at any time.

Vulnerability reporting

[Example] Found a security issue? Email support@redactguru.com.