Security

Where your documents go.

You are being asked to upload a commercial contract. Here is exactly what happens to it, including the part that leaves.

What leaves, and what does not

Two things leave, and only two. To read your rate card, the contract’s text is sent to Anthropic’s API, which proposes a rate structure you then confirm line by line rather than have applied behind your back.

The second is mail. If your provider replies to a claim, their answer arrives at our inbound address, which is Resend, and the product fetches that message and its attachments to file against the claim. Both are listed on the privacy page with everyone else who touches your data.

Nothing else goes anywhere. The audit runs on your data in your database. The claim letter is generated for you to copy; the product never sends anything to your provider, and your provider is never told you are checking.

What crosses the line, and what staysYour documents, every table and the audit itself stay inside your organization. Two things cross: the contract's text goes out to Anthropic's API so a rate structure can be proposed, and your provider's reply to a claim comes in through Resend. Your 3PL is never contacted.Stays insideYour documentsprivate bucket, keyed to your orgEvery tablerow-level security, fails closedThe audit itselfdeterministic, runs on your rowsNo service-role key exists in therequest path, so a bug cannotread across organizations.Crosses itthe contract’s textAnthropic APIso a rate structure can be proposedtheir reply to a claimResend inboundfetched and filed against the claimnothing, everYour 3PLnever told you are checkingWhat crosses the line, and what staysYour documents, every table and the audit itself stay inside your organization. Two things cross: the contract's text goes out to Anthropic's API so a rate structure can be proposed, and your provider's reply to a claim comes in through Resend. Your 3PL is never contacted.Stays insideYour documentsprivate bucket, keyed to your orgEvery tablerow-level security, fails closedThe audit itselfdeterministic, runs on your rowsNo service-role key in the request path.Crosses it→Anthropic APIthe contract’s text, to proposea rate structure you confirm←Resend inboundtheir reply to a claim, filed×Your 3PLnothing, ever · never told

Where the documents sit

In a private storage bucket — not public, enforced at the database rather than by convention. Object paths are keyed to your organization, and the policy that reads them fails closed: a path it cannot parse is denied rather than allowed.

documents bucket · public = false
path scheme · <organization_id>/<uuid>-<filename>
policy · denies when the leading segment is not your org, or does not parse

Row-level security, on everything

Every table in the system carries row-level security, and every policy asks the same question: are you a member of the organization that owns this row. Rate cards, invoices, activity, audit results, discrepancies, disputes, billing — all of it.

The application never holds a key that can bypass those policies. There is no service-role credential in the request path, so a bug in the application cannot read across organizations even if it tries.

What we cannot honestly claim yet

No SOC 2. No penetration test. No security questionnaire on file. The architecture above is real and verifiable in the code, but it has not been audited by anyone outside this project, and saying otherwise would contradict the one thing this product is for.

If you need a signed attestation before uploading a commercial contract, you should not upload one yet. Send a redacted rate card to the free audit instead and judge the output.