How we keep you safe
This page describes the controls Contenter has in place today. It's maintained by the Contenter team and is not an independent certification.
Content stays on your device
Signatures are generated in your browser using the Web Crypto API. Your original files never leave your machine, which means the worst-case impact of a breach on our side cannot include leaked content.
Authentication
We support email and password sign-in and Google sign-in. Passwords are checked against known breach databases at signup. Sessions are bound to a secure, httpOnly token issued by our identity provider.
Data isolation
Every record in our database is scoped to its owner with row-level security policies. Your signatures, takedowns, and account metadata are only readable by you (and our on-call engineers under controlled break-glass procedures).
Infrastructure
We run on managed cloud infrastructure with encryption in transit (TLS 1.2+) and encryption at rest. Backups are encrypted and retained on a rolling 30-day window.
Reporting a vulnerability
Found something? Email security@contenter.app with a description and reproduction steps. We acknowledge reports within two business days and credit responsible disclosure when requested.
