Security and data

How your files and your clients' uploads are protected. Only what is in place today.

Last updated: 2026-08-09.

Getting into your account

  • Passwords are never stored in the clear: we keep only a fingerprint of yours, and we would be unable to tell you what it is.
  • You can sign in with a passkey, using your device's fingerprint or face, with no password to type or remember.
  • Two-factor authentication is available, with recovery codes to keep somewhere safe.
  • Sign-in attempts are rate-limited, and a failed attempt leaves no address in the journal.

Every workspace is walled off

All business data belongs to a workspace, and that boundary is applied at the level of the queries themselves rather than only of the screens: data from another workspace does not come back, even when its address is aimed at directly.

Inside a workspace, you decide what each colleague may do, and every refusal is checked on the server, never only by hiding a button.

The files

No file is reachable through a guessable address: each one is stored under a random name that keeps nothing of yours, and the application is what serves it to you, having checked every single time that whoever is asking is allowed to open it.

What you deliver stays closed until you open it, or until the payment arrives if that is the condition you chose. That lock is checked on every download, not only when the page is drawn.

The links sent to your clients

A client has no account: their link is their key. Those links are signed, unguessable, and reveal nothing about your business: not how many jobs you have, nor since when. A form that has been answered cannot be opened a second time.

Knowing what happened

Every write in your workspace leaves a trace: who, what, when, from where. You can read it. Passwords and two-factor data are excluded from it.

In transit

Everything exchanged with the application goes over an encrypted connection.

Reporting a vulnerability

If you find something, write to the security address given in the legal notice, with enough for us to reproduce it. We acknowledge receipt and keep you posted on the fix. No action will be taken against good-faith research that has neither degraded the service nor read anybody else's data.

Legal notice

  • Publisher : Auroracode, entreprise individuelle (micro-entrepreneur)
  • Phone : +33 6 99 48 52 06
  • Registration : SIRET 878 256 775 00031, APE 6201Z
  • Responsible for publication : Thomas Drumont
  • Contact : [email protected]
  • Security reports : [email protected]
  • Host : netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Allemagne