Ask a human
waxTable

Security & privacy

Data security at waxTable

Your documents are encrypted in transit and at rest, kept logically separate per workspace, and reachable only by the people you've granted access — here's how that works in practice.

5 min readUpdated 18 Jun 2026

Our security principles

waxTable holds the documents that win and run your work — proposals, contracts, invoices and the client context behind them. We treat that data as yours, and we design for a small number of plain principles rather than buzzwords.

  • Encrypt data in transit and at rest by default.
  • Keep each workspace's data logically isolated from every other workspace.
  • Grant access on a least-privilege basis — people see only what their role allows.
  • Keep a tamper-evident record of significant actions.
  • Make your data portable and erasable on request.

Encryption

Traffic between your browser and waxTable is protected with industry-standard transport encryption (HTTPS/TLS), so your documents and credentials are not exposed on the network. Stored data — your documents, brand assets and account details — is encrypted at rest.

Isolation and access

waxTable is organised as Workspace > Project > Document. Data is scoped to your workspace and isolated from others. Within your workspace, access is governed by the roles you assign — not everyone needs to see everything.

The controls in your hands

Security isn't only what we do on the server — it's also the habits you adopt. A few minutes of setup makes a real difference.

  1. Turn on multi-factor authentication

    Add a second factor for every account that can edit or send documents. See multi-factor authentication.

  2. Right-size each person's role

    Give people the least access they need to do their job, and review it as the team changes.

  3. Use approvals for anything that goes out

    An internal sign-off step catches mistakes before a document leaves your workspace — see approval ladders.

  4. Review the audit log periodically

    Check who did what with the audit log, especially after staff changes.

Documents you send

When you send a document from your own domain and track opens and reads, recipients view it through a link. Treat shared links as you would any business document: share them with the intended recipient, and re-issue if circumstances change.

Reporting a problem

If you believe you've found a vulnerability or notice anything unusual on your account, tell us. We'd much rather hear about it early.

Reach us through contact support or email support, with enough detail for us to reproduce and investigate.

Frequently asked questions

Is my data encrypted?

Yes. Data is encrypted in transit with TLS and encrypted at rest. This is on by default for every workspace.

Can other waxTable customers see my documents?

No. Each workspace's data is logically isolated, and access requires being an authenticated member of that workspace.

Does Waxe use my documents to train models?

Waxe uses your brief and brand to draft your document for you. For how we handle personal data and our processing commitments, see Privacy, GDPR & the DPA.

What happens to a document after I send it?

The version in your workspace stays under your control. The recipient sees the copy you sent; sharing it further is their choice, so send links to intended recipients only.

Do you have a specific compliance certification?

For the current status of our compliance programme and any reports we can share under NDA, email support — we'd rather give you an accurate answer than a label.

Still need a hand?

Waxe answers most questions right inside the app. For everything else, our team replies within one business day.

Email support