Security

How we protect your work and your clients' data

Clientwharf holds files and messages that you share with your clients, so we keep the setup simple, private by default and described honestly. This page explains what we do today. We do not hold security certifications such as SOC 2 or ISO 27001, and we will not claim them until we do.

Where your data lives

Clientwharf runs on established infrastructure providers. The application is hosted on Vercel in the United States. The database is managed PostgreSQL on Neon, also in the United States. Uploaded files are stored in Cloudflare R2. The full list of providers, what each one does and where it processes data is on our subprocessors page.

Encryption

All traffic to clientwharf.com, the client portals and file downloads uses TLS (HTTPS). Data is encrypted at rest by our providers: Neon encrypts the database storage and Cloudflare encrypts objects stored in R2.

Private file storage

Files are never published on open, public download pages. Specifically:

  • Files are kept in a private storage bucket that cannot be browsed or listed from the internet.
  • When someone downloads or previews a file, Clientwharf checks that they are allowed to see it and then issues a signed link that expires after a few minutes.
  • Only your team and the invited contacts of the client a project belongs to can get those links.
  • Executable file types, such as .exe, .msi and script files, are blocked at upload by default.

Tenant isolation

Each workspace is a separate tenant. Every query for workspace data in our data layer is scoped to the workspace of the signed-in user, and IDs that come from the browser are checked against that workspace before anything is read or changed.

Client portals are scoped twice: to the workspace and to the single client the contact belongs to. A client contact can only see their own portal. Automated tests attempt cross-workspace and cross-client access and check that every attempt is refused.

Accounts and access controls

  • Team members have a role in each workspace (Owner, Admin or Member), and sensitive actions are limited by role.
  • Team members can turn on two-factor authentication with an authenticator app (TOTP), with backup codes for recovery.
  • Email addresses are verified before a team member can invite clients or teammates.
  • Client contacts sign in with single-use magic links sent to their email, which expire after 15 minutes. They do not need a password.
  • Sign-in, sign-up, password reset, two-factor, upload, invite and contact form endpoints are rate limited.
  • Session cookies are secure and HTTP-only, and resetting a password signs out other sessions.

Audit events

Clientwharf records audit events for sensitive actions, including role changes, invitations, deletions, data exports, approval decisions and billing changes. On Agency Plus and Scale, workspace owners and admins can review these events in the activity log.

Approval decisions are stored as permanent records with the name and email of the person who decided, the file version and the time. They cannot be edited after the fact.

Backups and recovery

The database is backed up by Neon, which supports point-in-time restore. We keep a documented restore procedure so the database can be recovered to an earlier point if needed.

You can also export your own workspace at any time, including all files and a JSON and CSV copy of your projects, approvals and comments. See how to export your data.

Payments

Subscription payments are handled by Paddle, our reseller and merchant of record. Card and payment details are entered in Paddle's checkout and are never sent to or stored by Clientwharf.

Clientwharf does not process payments between you and your clients. Quotes and invoices in Clientwharf are documents only.

Privacy and data processing

When you store your clients' information in Clientwharf, we process it on your behalf. Our Data Processing Addendum describes the security measures, subprocessors and breach notification commitments that apply. Our Privacy Policy explains how we handle account and website data.

Reporting a vulnerability

If you believe you have found a security issue in Clientwharf, please email security@clientwharf.com with a description, the steps to reproduce it and any relevant URLs. Our contact details are also published in /.well-known/security.txt.

We ask that you:

  • Only test against your own account and workspace, never against other customers' data.
  • Avoid actions that could degrade the service, such as load testing or automated scanning at high volume.
  • Give us reasonable time to investigate and fix the issue before sharing details publicly.

We will acknowledge your report, keep you informed while we investigate and let you know when it is resolved. We do not currently run a paid bug bounty program.

Something else?

For abuse of the service, use the abuse report form. For other questions, see contact.