Security & privacy

How Holdfast handles your vendor book

Accounts

Workspaces are private to the signed-in user. Server functions that read or write contracts require an authenticated session and scope every query by that user id. There is no client-supplied user id.

Data we store

Vendor names, dates, notice terms, spend amounts, letter drafts, and optional pasted contract text. Do not store secrets, payment card numbers, or government IDs in notes.

AI extraction

On the Firm plan, pasted clauses may be sent to the xAI API to extract dates and notice periods. Extraction is user-initiated. Confirm extracted fields before saving. Disable this by staying on Free or Desk.

Encryption & hosting

Production traffic is served over HTTPS. Application data lives in Postgres. Backups and retention are described in the owner operations guide. This page is an overview, not a SOC 2 report.

Not legal advice

Holdfast does not file notices, certify service, or interpret your contract. Wrong notice terms produce wrong action dates. Always match the tracker to the signed agreement.