Security at ContractVerfAi

Your contract documents are sensitive. We built our infrastructure with security as the foundation, not an afterthought.

๐Ÿ‘๏ธ

Your Data, Your Eyes Only

We never use your contracts to train AI models, and we never sell your data to anyone โ€” not to advertisers, not to data brokers, not to anyone. Full stop.

๐Ÿ”’

Encryption at Rest

All documents encrypted with AES-256 via AWS S3. Database encrypted with AWS RDS encryption.

๐Ÿ”

Encryption in Transit

All connections use TLS 1.2+. HTTPS enforced everywhere with HSTS headers.

๐Ÿ›ก๏ธ

WAF Protection

AWS WAF with managed rule sets protects against SQL injection, XSS, and other OWASP Top 10 threats.

๐Ÿ”‘

Zero-Knowledge Auth

Passwords are never stored. AWS Cognito manages authentication with SRP protocol and optional TOTP MFA.

โฑ๏ธ

Auto-Delete

Your contract documents are automatically deleted from storage after 90 days.

๐ŸŒ

Private Network

Our database and AI processing infrastructure runs in a private VPC, inaccessible from the public internet.

๐Ÿ”

Secrets Management

All API keys and credentials stored in AWS Secrets Manager, never in code or environment variables.

๐Ÿ“Š

24/7 Monitoring

CloudWatch alarms alert our team instantly on errors, unusual activity, or infrastructure issues.

Infrastructure

Built entirely on AWS (us-east-1). Aurora Serverless v2 ยท S3 ยท CloudFront ยท Cognito ยท Lambda ยท SQS ยท SES ยท WAF ยท Secrets Manager

Found a security issue? security@contractverifai.com