Security at Proofmark

Proofmark exists to keep records people can rely on. Here is specifically how your files and approval records are protected — no vague promises.

Private file storage

Deliverables are stored in private buckets, never on public URLs. Files are only reachable through the application after an access check — there is no direct public path to your work.

Token-protected access

Clients access a project through a unique, unguessable handover link. Approval links carry their own single-purpose tokens. Every request re-validates the token server-side before anything is returned.

SHA-256 file hashing

Each deliverable is hashed with SHA-256 at upload. The hash travels with the file, appears on the proof certificate, and is re-verified when the file is downloaded, so tampering or corruption is detectable.

Recorded approvals

Client sign-off is recorded with a UTC timestamp and the IP address of the approval, tied to the specific project version being approved. Approval records cannot be edited from the UI after the fact.

Instant access revocation

You can revoke a client handover link at any time. Revocation takes effect immediately: open portals are redirected, and download requests against the old link are refused.

Payment-gated unlock

Final files marked as payment-gated stay locked until payment is confirmed. The lock is enforced on the server at download time — not just hidden in the interface.

Payments

Subscription billing is processed by Dodo Payments; Proofmark never stores your card details. Project payments between you and your client happen through the payment method you choose (bank transfer, payment link, and similar) — Proofmark records the payment state and gates file access on it, and takes no commission.

Data retention

Your projects, approval records, and deliverables remain available for as long as your account is active. When you delete a project or your account, the associated files and records are removed from the application. See the privacy policy for details.

Responsible disclosure

Found a vulnerability? Email support@proofmark.space with steps to reproduce. We read every report and will respond as quickly as we can. Please give us reasonable time to fix an issue before disclosing it publicly.

What we do not claim

Proofmark keeps honest records — it does not promise legal outcomes. We do not claim “bank-grade security,” guaranteed dispute protection, or that our records are legally binding in every jurisdiction. Proofmark helps you keep records of approval, delivery, and payment status; it is not a substitute for legal advice. For how the proof model works and what certificates mean, read the trust center.