Security · the part most services bury
Security, in plain terms
Short version: we hold as little as we can, we encrypt the sensitive part of it, and we say plainly where that stops.
How your data is protected
PROTECTIONS · P. 01Encrypted before it is written
Sensitive fields — identifier numbers, notes, legal names — are encrypted in our application code before they are written to the database. Everything moves over TLS 1.3 in transit. Standard primitives, no custom cryptography.
Your sign-in
A password is never enough on its own: signing in with one always asks for a six-digit code emailed to you. A passkey skips the code, because it is already two factors. There are no SMS codes anywhere in the product — a code sent by text can be stolen by taking over your phone number, so we never send one. Every session is listed in settings and can be revoked remotely.
Masked by default
Identifiers display masked (••••••382) everywhere. Revealing one requires re-authenticating, the revealed value re-masks automatically after 60 seconds, and the app works fine if you never enter an identifier at all.
Nothing stored
Your photo is read where the product runs, never sent to an outside service, and discarded when the response returns. What remains is the three fields you confirm, and nothing saves until you do.
Nothing rides along
We do not sell data, run ads, or load third-party trackers on signed-in pages. No scripts, fonts, or images load from third-party hosts anywhere in the product. This site sets no cookies at all, which is why there is no cookie banner.
Short retention is a security control
RETENTION · P. 02Data that no longer exists cannot leak. Holding less, and holding it briefly, is the protection we lean on hardest.
- Scan images: not stored at all. Read during the request and discarded when it returns. Everything on the document beyond the three fields goes with it.
- Extracted fields awaiting confirmation: one hour. Document type, issuer and expiration date wait for you to confirm them, then go.
- The honest maximum: 30 days. Deleted rows go immediately, but database restore history takes up to 30 days to expire. That is the longest any trace of deleted data survives anywhere we control.
MINUTE 46 OF 60
The three candidate values wait one hour for your confirmation, then are deleted.
Export and deletion are self-serve
THE EXIT · P. 03Export everything your account holds — items, dates, and the identifiers and notes you entered — in machine-readable form, from settings, on every tier, any time.
Deleting your account is the same: you do it yourself, without emailing anyone. Sign-in is disabled and sessions are revoked immediately, everything is purged from production within 24 hours, and database restore history expires within 30 days.
What we do not claim
NOT CLAIMED · P. 04- We hold no audits or certifications — no SOC 2, no ISO 27001. We are not HIPAA-covered, and we avoid PCI scope rather than certify within it. We will claim a penetration test only once one has actually happened.
- We are not a document store. Nothing you scan is kept. We hold dates, not documents, and anything you need to keep should live somewhere built for it.
- We cannot make deletion instantaneous everywhere. Live copies go at once; database restore history takes up to 30 days to expire.
- Nothing here is a guarantee against breach. This page describes what we built and where it stops. Any service claiming more is describing its marketing.
Report a vulnerability
REPORTING · P. 05Write to security@validthru.app. We acknowledge every report within 72 hours, a person owns it from there, and we keep you informed until the issue is resolved. We do not pursue legal action against good-faith research, and we credit reporters who want credit. Our security.txt carries the same contact.