Security

We can't read your data.

Everything you share in doconvoy is encrypted on your device before it reaches our servers. We store only the scrambled result — and we don't hold the keys to unlock it.

1

Encrypted on your device

Your secret is locked in your browser before it's sent. The plain text never leaves your device.

2

We store only ciphertext

Our servers receive scrambled data — no keys, no plain text. Nothing we could read or be compelled to hand over.

3

Only the right person can open it

The key rides in the share link, or stays inside your team's encrypted workspace. Only the intended recipient can unlock the content.

End-to-end encryption

Content is unreadable from the moment you create it until the moment it's opened — including to us.

Layered access controls

Add email verification, a passcode, allow and deny lists, view limits, and expiry to any link. Encryption protects the content; these decide who can open it.

A complete audit trail

Every share, access, and change is recorded in an immutable, exportable log — evidence you can show without revealing what was shared.

You hold the keys

Keys live on your devices and inside your encrypted workspace. Rotate them anytime — for example, when someone leaves the team.

Answers to the questions we hear most about encryption, data handling, recipient access, and audit logging.

Read the security FAQ

Responsible disclosure

How to report a security vulnerability responsibly.

Reporting a vulnerability

If you believe you have discovered a security vulnerability in doconvoy, we ask that you disclose it to us responsibly before making it public.

Send your report to: security@doconvoy.com

What to include

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any proof-of-concept code or screenshots (if applicable)
  • Your contact information for follow-up

Our commitments

  • We will acknowledge your report within 2 business days
  • We will keep you informed of our progress toward a fix
  • We will not take legal action against researchers who disclose responsibly
  • We will credit researchers who wish to be credited, upon request

Scope

Reports are welcome for vulnerabilities in the doconvoy web application (app.doconvoy.com), the marketing website (doconvoy.com), and our core encryption implementation.

Out of scope: social engineering attacks, physical attacks, denial-of-service attacks, and vulnerabilities in third-party services we depend on.

Coordinated disclosure

We ask that you give us a reasonable timeframe (typically 90 days) to investigate and remediate confirmed vulnerabilities before public disclosure. We're committed to working with you to resolve issues promptly.

Ready to share sensitive data without handing it to a third party?

Start sharing securely