Trust

Security & data handling

Acretix helps you draft and run outcome-based contracts. Here is how we protect the deals, documents, and evidence you put in — in plain terms, and true to how the product actually works.

Accounts & authentication

Link to this section
  • Accounts are handled by Supabase Auth. Sign in with a password or a one-time magic link sent to your email.
  • Your session is managed by Supabase Auth via cookies and re-validated on the server on every request.
  • You can turn on an authenticator app under Settings, Security; sign-in then asks for its 6-digit code.
  • Settings, Security lists your account's sign-ins and sign-in attempts from the last 90 days, with the network each came from.

Your data is isolated

Link to this section
  • Every deal, measurement, and file is tied to its owner. Postgres row-level security (RLS) enforces — in the database itself, not just in our app code — that you can only read and write your own records.
  • The only other access is through explicit, database-enforced policies — our review staff handling a submission, or a counterparty you invite to a deal. Nothing is shared by default.

Documents & evidence

Link to this section
  • Evidence files live in a private storage bucket that is never publicly listable.
  • They are served only through signed links that expire after one hour, generated fresh each time you open a file — and access to the bucket follows the same per-deal rules as the rest of your data.
  • Each upload is fingerprinted with a SHA-256 hash, and the evidence set is frozen once a settlement cycle is verified, so the proof behind an agreed number is tamper-evident.
  • Acretix keeps a copy of each signed contract. The deal's parties can download it from the deal, and the copy is also kept in the encrypted backups.
  • When a contract is ready to sign, it is routed through eSignatures.com, a dedicated e-signature provider that collects each party's signature.
  • We verify the cryptographic signature (HMAC-SHA256) on every completion callback before trusting it, so a forged notification cannot mark a contract as signed.

Card and bank details

Link to this section
  • Acretix never sees or stores card or bank numbers.
  • Where a firm takes payment through Acretix, the payor pays on Stripe's own page, straight into the firm's own Stripe account.

AI assistance is opt-in

Link to this section
  • AI features are off by default. You switch them on per account under Settings → AI.
  • When enabled, your draft text is sent to Anthropic's Claude API for drafting suggestions. When AI review is used, evidence is sent to Anthropic for the AI judge and rubric induction, and to Together AI (open models), which is not used while the AI judge is off.
  • A per-account usage budget caps how much is processed. With AI off, the wizard, templates, and document export work exactly the same.

Secrets stay on the server

Link to this section
  • The browser only ever receives our public Supabase key, which is safe by design and constrained by row-level security.
  • Service-role keys and every third-party API key are server-only and are never shipped to the client.

Infrastructure

Link to this section
  • The app runs on Vercel; the database, authentication, and file storage run on Supabase (managed PostgreSQL).
  • Traffic is encrypted in transit with HTTPS/TLS, and data is encrypted at rest by those providers.
  • Cloudflare, Inc. (USA) holds the encrypted database backups and copies of the evidence files, including signed contracts.
  • Acretix sends sign-in codes, notices, digests and reminders from tryacretix.com, and never sends bulk or marketing email from it.

Report a security issue

Link to this section

Found something? Email support@acretix.io. We will send a first reply within one business day.

Read our vulnerability disclosure policy

Last updated 1 October 2026.

Support: support@acretix.io