Security

Encryption at rest

Every uploaded document is sealed under a fresh per-document Data Encryption Key (DEK). The DEK is wrapped under a server master key held in Azure Key Vault, accessed by the runtime via a Managed Identity scoped to get + list on a single vault. The plaintext document never persists; only the sealed bytes plus the wrapped DEK live on disk and in the database.

Encryption in transit

TLS 1.2+ on every public endpoint. HSTS enforced. Database connections require SSL.

Authentication

Every access link is single-use and lands on an SMS second-factor before a session is issued. The URL token (256-bit cryptographic random) is consumed atomically on click and never opens the document by itself — the recipient must enter a 6-digit code sent to the cell phone on file. On success, we mint an httpOnly session cookie (4-hour expiry) bound to that document; a forwarded URL cannot open the document because it cannot receive the SMS.

Audit log

Every access attempt (successful or failed) is recorded with timestamp, IP, user-agent, and document. The full evidence-chain export (downloadable from the dashboard) includes this log for any legal proceeding.

Infrastructure

Responsible disclosure

If you find a vulnerability please email support@redlines.law with full details. We will respond within 72 hours. Please do not publicly disclose until we have had a reasonable window to remediate.

What we are still building

We are working towards SOC 2 Type II. We do not yet have HIPAA / FedRAMP / ISO 27001 certifications. If your engagement requires a specific compliance regime, contact us before uploading.