← TransactFile

Security

Every file you manage holds someone’s largest purchase. Here is how that data is treated. Everything on this page describes what runs today, not plans.

Last updated August 29, 2026.

Your workspace is isolated

Every record belongs to exactly one workspace, and the separation is enforced by the database itself with row-level security, not just by application code. A login can only ever read its own workspace, and the workspace identity is set server-side where clients cannot forge it.

Your documents stay in your Drive

Contracts and file documents live in your own Google Drive, in folders TransactFile organizes for you. We do not run a separate document store, so leaving the service never means losing your documents; they were yours the whole time.

No passwords to steal

Sign-in is Google sign-in or a one-time link sent to your email. TransactFile stores no passwords, and workspaces are invitation-only: an address that has not been invited has nothing to sign into.

Email drafts, sent by you

TransactFile writes drafts into your own mailbox, Gmail or Outlook, and stops there. Nothing is sent on your behalf: every email that reaches an agent or client was reviewed and sent by you, from your real address.

Encrypted everywhere

Every connection to TransactFile negotiates TLS 1.3, plain HTTP is refused outright, and browsers are told to never try it again (HSTS, two years, subdomains included). All workspace data in the database, from tasks and contacts to deadlines and notes, is encrypted at rest with AES-256 by our database provider, and the database is backed up daily. Your documents are encrypted at rest by Google in your own Drive. Google account access uses OAuth with the narrowest flow we can offer, honoring Google’s Limited Use policy as described in the Privacy Policy.

AI that reads, never trains

Contract extraction and addendum reading run on Anthropic’s Claude, and on nothing else. Data sent through Anthropic’s API is not used to train models, theirs or anyone’s, and TransactFile opts into no data-sharing program. Every value the AI reads is shown to you beside the source text for your confirmation before it touches the file; nothing applies itself.

Access ends when you say so

Team access is deliberate: coverage for a helper is granted for a date window and expires by itself, and deactivating a member cuts their sign-in immediately, not at their next login. Share links for agents and clients are unguessable, revocable, and show only the facts you chose; fees and private notes are never in that data.

A record that cannot be rewritten

Every file keeps an activity trail: what was added, sent, filed, completed, and by whom, and settings changes are recorded too. The trail is append-only at the database itself: no login, ours or yours, can edit or delete a history row. Public endpoints are rate-limited, and every dependency in the codebase is watched for published vulnerabilities, with fixes proposed automatically the day an advisory lands.

No lock-in, by design

Your documents already live in your own Drive, so there is nothing to export there. The accountant export covers your billing rows today, and a full export of your workspace data is yours for the asking. No lock-in is a design rule, not a promise.

Who we build on

Four providers touch workspace data, each carrying an independent SOC 2 attestation: Vercel hosts the application, Supabase runs the database, Google holds your documents and mail where they always were, and Anthropic powers the contract reading. There is no fifth; we do not sell data or run ads.

What we do not claim

TransactFile holds no SOC 2 attestation of its own yet and offers no separate two-factor prompt: sign-in security rides on your Google account or your mailbox, which is also where your second factor belongs. When that changes, this page changes.

Found something?

If you believe you have found a security issue, write to angela@masterkeytc.com and it will be read the same day.