Security & privacy
How Holdfast handles your vendor book
Accounts
Workspaces are private to the signed-in user. Server functions that read or write contracts require an authenticated session and scope every query by that user id. There is no client-supplied user id.
Data we store
Vendor names, dates, notice terms, spend amounts, letter drafts, and optional pasted contract text. Do not store secrets, payment card numbers, or government IDs in notes.
AI extraction
On the Firm plan, pasted clauses may be sent to the xAI API to extract dates and notice periods. Extraction is user-initiated. Confirm extracted fields before saving. Disable this by staying on Free or Desk.
Encryption & hosting
Production traffic is served over HTTPS. Application data lives in Postgres. Backups and retention are described in the owner operations guide. This page is an overview, not a SOC 2 report.
Not legal advice
Holdfast does not file notices, certify service, or interpret your contract. Wrong notice terms produce wrong action dates. Always match the tracker to the signed agreement.