ServeDocX security model
Security controls built into the commercial application architecture.
Application
- Authenticated tenant accounts and role-based access
- Server-enforced tenant IDs on operational records
- CSRF protection and login throttling
- Email verification for purchaser accounts
- Stripe webhook signature verification and idempotent event logging
Evidence
- Private HostGator file storage outside the public web directory
- Original and stamped-photo separation
- SHA-256 fingerprints
- SHA-256 fingerprints, metadata sidecars and audit events
- Short-lived secure download links
