Ask a human
waxTable

Security at waxTable

The documents you draft in waxTable are the ones that win and run your business. We protect them like the originals in a locked filing cabinet — encrypted, isolated, and access-controlled at every layer.

This document is written in English. The English version is authoritative, and any translation is provided for convenience only.

TLS 1.2+Encrypted in transit, on every request
AES-256Encrypted at rest across databases, storage, and backups
Per-workspaceRow-level isolation enforced at the database layer
MFARequired for Owner & Admin roles on Business and Enterprise
AnnualIndependent third-party penetration testing

Security isn't a page we wrote once. It's how the product is built: every workspace is sealed off from every other, every byte is encrypted coming and going, and the most sensitive actions demand a second factor. Here is exactly what that means.

01

Encryption, in transit and at rest

Every request to and from waxTable travels over TLS 1.2 or higher. Nothing — not a brief you paste in, not a finished proposal, not a single keystroke — crosses the network in the clear.

Data at rest is encrypted with AES-256 across our databases, object storage, and backups. Encryption keys are managed by our infrastructure provider and rotated on their schedule, so a stolen disk is just noise.

TLS 1.2+ · AES-256
In transit and at rest, on every request and every byte — encryption isn't a setting you opt into, it's the default everywhere.
02

Tenant isolation by design

waxTable is multi-tenant, but your workspace behaves as if it were the only one. Every read and write is gated by row-level security predicates enforced at the database layer and checked against your membership — not by application code that could be bypassed.

The practical result: cross-workspace access is impossible by design. A bug in a feature can't leak another customer's documents, because the data store itself refuses to return rows you don't own.

03

Authentication & access control

You decide who gets in, and how hard it is to do so.

  • Sign in with Google or Microsoft OAuth, or with an email magic-link or password.
  • MFA is required for Owner and Admin roles on Business and Enterprise plans.
  • Session lifetime, IP-pinning, and device-trust controls are available on Business and Enterprise plans.
  • Granular roles keep teammates scoped to the workspaces and documents they need — nothing more.
04

Infrastructure & data residency

waxTable runs on hardened, globally distributed cloud infrastructure with managed patching and network-level protections in front of every service.

Need your data to stay in a particular region? The primary processing region is configurable per workspace on Enterprise plans, and Standard Contractual Clauses are available where cross-border transfers require them. See the Data Processing Addendum for the full terms.

05

Your content stays yours

The documents Waxe drafts belong to you. We process your content for one purpose: to generate, render, and deliver your documents and run the service you're paying for.

  • We never sell your content, and we never share it for advertising.
  • Operational telemetry we collect — errors, latencies — never includes your document content.
  • Export or delete your data on request; closing an account removes it on our published retention schedule.
06

Backups, logging & resilience

Encrypted backups are taken on a regular schedule so a bad day never becomes a lost document. Sensitive, security-relevant actions are written to an append-only audit log that operators can review but cannot quietly rewrite.

On Business and Enterprise plans, workspace admins can review their own audit trail — who did what, and when — directly from settings.

07

Independent testing

We commission annual third-party penetration testing on Business and Enterprise plans. Findings are triaged and remediated on a risk-prioritised schedule.

Evaluating waxTable for your firm? Summary reports and a walkthrough of our controls are available under NDA for prospective Enterprise customers — email security@waxtable.com.

08

Responsible disclosure

If you believe you've found a vulnerability, we want to hear from you before anyone else does. Email security@waxtable.com with enough detail to reproduce the issue. Here's what happens next:

  1. We acknowledgeWithin 24 hrs

    Every report gets a human reply within a day — you'll know it landed.

  2. We triageWithin 72 hrs

    We reproduce, assess severity, and tell you what we're doing about it.

  3. We remediateRisk-prioritised

    Fixes ship on a severity-driven schedule, and we close the loop with you.

Report a concern

See something? Tell our security team.

Vulnerability reports, security questionnaires, and Enterprise due-diligence requests all land in the same place. We answer fast.

Authorised signatory

Email security@waxtable.com

We acknowledge within 24 hours and aim to triage within 72.