Our security principles
waxTable holds the documents that win and run your work — proposals, contracts, invoices and the client context behind them. We treat that data as yours, and we design for a small number of plain principles rather than buzzwords.
- Encrypt data in transit and at rest by default.
- Keep each workspace's data logically isolated from every other workspace.
- Grant access on a least-privilege basis — people see only what their role allows.
- Keep a tamper-evident record of significant actions.
- Make your data portable and erasable on request.
Encryption
Traffic between your browser and waxTable is protected with industry-standard transport encryption (HTTPS/TLS), so your documents and credentials are not exposed on the network. Stored data — your documents, brand assets and account details — is encrypted at rest.
Isolation and access
waxTable is organised as Workspace > Project > Document. Data is scoped to your workspace and isolated from others. Within your workspace, access is governed by the roles you assign — not everyone needs to see everything.
- Access requires an authenticated account that's a member of the workspace.
- What a member can view or change is set by their role — see team members and roles.
- Finer-grained controls are described in permissions.
- You can add a second login factor — see multi-factor authentication.
The controls in your hands
Security isn't only what we do on the server — it's also the habits you adopt. A few minutes of setup makes a real difference.
Turn on multi-factor authentication
Add a second factor for every account that can edit or send documents. See multi-factor authentication.
Right-size each person's role
Give people the least access they need to do their job, and review it as the team changes.
Use approvals for anything that goes out
An internal sign-off step catches mistakes before a document leaves your workspace — see approval ladders.
Review the audit log periodically
Check who did what with the audit log, especially after staff changes.
Documents you send
When you send a document from your own domain and track opens and reads, recipients view it through a link. Treat shared links as you would any business document: share them with the intended recipient, and re-issue if circumstances change.
Reporting a problem
If you believe you've found a vulnerability or notice anything unusual on your account, tell us. We'd much rather hear about it early.
Reach us through contact support or email support, with enough detail for us to reproduce and investigate.