Menu

What we actually do about security.

Files are encrypted in transit and at rest. Every action is logged with who, what and when. Clients sign in with a one-time link rather than a password, so there's no shared credential to leak. Each firm's data is separated twice: in our code and again in the database itself.

We are not SOC 2 certified. We'd rather tell you that than imply otherwise.

Encryption in transit and at rest

Every connection to Denby uses HTTPS with HSTS, so browsers refuse unencrypted connections. Files are stored in Cloudflare R2 and the database in Neon Postgres, both encrypted at rest by the provider.

Files never pass through or get served from the Denby app itself. Uploads go straight to storage, and every download uses a link that expires after five minutes.

Access controls and roles

Each firm is a separate tenant. Every query for a firm's data is scoped to that firm by our code, and the database enforces the same separation a second time with row-level security, so a bug in one layer can't expose another firm's data. Automated tests try to read, change and list one firm's data as another, and must fail.

Inside a firm, people are owners, admins, staff or viewers. Only owners manage billing or delete the firm; viewers can't change anything. A client's contacts see only their own client page.

Why clients sign in with a link instead of a password

Clients enter their email address and receive a one-time link that works once, for 20 minutes. We store only a fingerprint of each link, never the link itself. Opening the link shows a button to continue, so email security scanners that visit links can't use it up.

No password means nothing for a client to reuse from another site, write on a sticky note or share with a colleague. Each device stays signed in for 30 days. Removing a contact, or archiving their client, ends their access at once.

Your team signs in with a password or an email link, and can add two-step sign-in with an authenticator app. Owners of paid firms must use it.

Audit logging

Every sign-in, upload, download, approval, invoice change and settings change is recorded with who did it, when, and from which IP address. Owners and admins on the Firm plan and above can export the log as a CSV. We keep audit records for 24 months.

File handling and scanning

Every uploaded file is checked before anyone can download it. We confirm its contents match its type, block executable files, and scan it with ClamAV on a server we run ourselves, so files are never sent to a third-party scanning service. Anything that fails is quarantined: the uploader is told, and the file is never offered for download.

Each plan sets a per-file limit, from 250 MB on Solo to 2 GB on Firm and Agency. Deleted files can be restored for 30 days, then are permanently removed from storage.

Where your data is stored

Denby stores data in the United States. The database runs with Neon in US East (Ohio), files are stored in Cloudflare R2 in eastern North America, and files being virus-scanned pass through our own ClamAV scanner on Google Cloud Run in US East (Ohio) without being kept there. Emails are sent from the United States by Resend.

We don't offer a choice of region yet. If your firm needs data kept in the European Union, email security@denby.app and tell us; it's on our list for the Firm plan.

Sub-processors

Denby runs on a small number of established providers for hosting, storage, database, email and billing. The sub-processor list names each one, what it does and where. We give customers notice before adding a new one.

Data export and deletion

Owners and admins can download everything at any time: every file, plus a JSON manifest of clients, contacts, requests, messages, approvals, invoices, form responses and the audit log. If a plan lapses, the account becomes read-only; nothing is held back.

When an owner deletes the firm, it disappears from Denby immediately and everything is permanently erased 30 days later, files first. The delay exists so a mistake can be undone by asking us.

Responsible disclosure

If you find a security problem, email security@denby.app. We reply within two working days, keep you informed while we fix it, and won't take legal action against good-faith research that avoids other people's data. Our security.txt has the details.

Set up your first client portal in 20 minutes.

14 days free. No card. Unlimited team members on every plan.