Security

Your clients trust you.
You can trust us.

BopDocs is built to handle sensitive client documents — tax records, legal files, financial statements. Security isn't a feature we added later. It's how we built the platform from day one.

AES-256

Encryption

SOC 2

Infrastructure

99.9%

Uptime target

HTTPS

TLS 1.2+ always

How We Protect Your Data

Encryption at Rest

All data stored in our database and file storage is encrypted using AES-256 — the same standard used by banks and government agencies.

Encryption in Transit

Every connection uses TLS 1.2+. Data is never transmitted in plaintext — not between your browser and our servers, and not between our services.

Row-Level Security

Every database query is filtered by organization at the database level. One org can never access another's data, even in the event of an application bug.

Password Security

Passwords are hashed with bcrypt and unique per-user salts. We never store plaintext passwords. Resets use time-limited, single-use tokens.

SOC 2 Infrastructure

BopDocs runs on Vercel (application) and Supabase (database and storage), both SOC 2 Type II compliant with redundancy and automated backups.

Access Controls

Role-based access (Owner, Admin, Member) controls who can manage team settings, send requests, and review submissions.

Team Security

Invites use 7-day expiring tokens sent to specific emails. Only the exact recipient can accept. Owners can revoke access at any time.

File Upload Safety

Files stored in isolated, access-controlled buckets. Types validated server-side. 25 MB limit. Only authenticated org members can access files.

Client Portal Security

Your clients access their upload portal through a unique, unguessable URL. No account creation required.

HTTPS for all connections
No tracking or analytics cookies
Access restricted to a single request
File types validated server-side
No other client data exposed
No organization internals visible

Data Backup & Recovery

Automated daily backups|Point-in-time recovery|Geographically separated storage|30-day retention

Incident Response

Investigate and contain immediately
Notify affected users within 72 hours
Provide detailed incident report
Implement measures to prevent recurrence

Responsible Disclosure

Found a vulnerability? Email security@bopdocs.com. We ask that you:

  • Do not access or modify other users' data
  • Do not publicly disclose before we address it
  • Provide enough detail to reproduce and fix

Security questions? Contact security@bopdocs.com. For data and privacy questions, see our Privacy Policy.

Ready to stop chasing?

Join professionals who’ve automated document collection and reclaimed their time.