Workspace isolation
Contract, member, schedule, and governance queries are scoped to the workspace in the authenticated server session. Client-supplied roles or workspace identifiers are not used as authorization evidence.
The access, audit, storage, and deletion controls currently implemented in ContractVault.
Version 2026-07-15 · Effective Date 2026-07-15 · Billing Policy RevisionContract, member, schedule, and governance queries are scoped to the workspace in the authenticated server session. Client-supplied roles or workspace identifiers are not used as authorization evidence.
Passwords are stored as one-way hashes. Browser sessions use HttpOnly and Secure cookies. Role changes, password resets, and member removal revoke existing sessions where applicable.
The server resolves source-document locations from authenticated workspace data. Original views, contract edits, member changes, and deletion requests are recorded as audit events.
Production contract files are encrypted at rest and in transit. Workspace deletion includes source files, structured contract data, accounts, and operational records, subject to legally required retention.
This page describes implemented controls and does not represent a third-party certification. Additional controls are listed here only after they are available in the self-service product.