Security
We can't read your data.
Everything you share in doconvoy is encrypted on your device before it reaches our servers. We store only the scrambled result — and we don't hold the keys to unlock it.
How it works
Encrypted on your device
Your secret is locked in your browser before it's sent. The plain text never leaves your device.
We store only ciphertext
Our servers receive scrambled data — no keys, no plain text. Nothing we could read or be compelled to hand over.
Only the right person can open it
The key rides in the share link, or stays inside your team's encrypted workspace. Only the intended recipient can unlock the content.
What protects your data
End-to-end encryption
Content is unreadable from the moment you create it until the moment it's opened — including to us.
Layered access controls
Add email verification, a passcode, allow and deny lists, view limits, and expiry to any link. Encryption protects the content; these decide who can open it.
A complete audit trail
Every share, access, and change is recorded in an immutable, exportable log — evidence you can show without revealing what was shared.
You hold the keys
Keys live on your devices and inside your encrypted workspace. Rotate them anytime — for example, when someone leaves the team.
Common questions
Answers to the questions we hear most about encryption, data handling, recipient access, and audit logging.
Read the security FAQResponsible disclosure
How to report a security vulnerability responsibly.
Reporting a vulnerability
If you believe you have discovered a security vulnerability in doconvoy, we ask that you disclose it to us responsibly before making it public.
Send your report to: security@doconvoy.com
What to include
- — A description of the vulnerability and its potential impact
- — Steps to reproduce the issue
- — Any proof-of-concept code or screenshots (if applicable)
- — Your contact information for follow-up
Our commitments
- — We will acknowledge your report within 2 business days
- — We will keep you informed of our progress toward a fix
- — We will not take legal action against researchers who disclose responsibly
- — We will credit researchers who wish to be credited, upon request
Scope
Reports are welcome for vulnerabilities in the doconvoy web application (app.doconvoy.com), the marketing website (doconvoy.com), and our core encryption implementation.
Out of scope: social engineering attacks, physical attacks, denial-of-service attacks, and vulnerabilities in third-party services we depend on.
Coordinated disclosure
We ask that you give us a reasonable timeframe (typically 90 days) to investigate and remediate confirmed vulnerabilities before public disclosure. We're committed to working with you to resolve issues promptly.
Ready to share sensitive data without handing it to a third party?
Start sharing securely