Trust and safety
Security and data handling
Where your invoices, quotes and client details live, how accounts are kept apart, and what Docketlane deliberately does not store.
- Invoices, quotes and calculators run in your browser — no account needed
- Row-level security is enabled and forced on every table holding tenant data
- Card numbers are never seen or stored by Docketlane
- Account deletion removes your records permanently
Docketlane is a drafting tool, not tax or legal advice.
How Docketlane handles your data
Docketlane holds invoices, quotes and client contact details — commercially sensitive records for a small business. This page sets out how that data is stored and separated, in plain terms, so you can judge it rather than take it on trust.
It describes how the product works today. Docketlane is early, run by a small team, and this page will change as the product does. It is not a certification and it is not a warranty; the Terms and Privacy Policy are the binding documents.
You can use most of it without an account
The invoice generator, the quote generator and every calculator run in your browser. Drafts are kept in your own browser storage, and nothing is sent to our servers until you choose to save a document to an account.
That means you can produce a document and download the PDF without giving us anything at all. If you never sign up, we never hold your invoice.
Separation between accounts
When you do save, your records live in a Postgres database hosted on Supabase. Every table that holds tenant data has row-level security enabled and forced, so the database itself refuses to return another account's rows — separation does not depend on the application getting a query right.
Writes that touch several tables at once go through database functions with fixed permissions rather than direct table access, so the rules are enforced in one place. The behaviour is covered by an automated database test suite that runs against a real Postgres instance, not mocks.
Where your data lives
The database holding your saved records runs in Sydney, Australia (AWS ap-southeast-2, hosted on Supabase). Your invoices, quotes and client details are stored onshore.
The website itself is served from a global content network so pages load quickly wherever you are, and unsaved drafts never leave your browser at all. If where your data is stored matters to a specific obligation your business has, confirm the details with your own adviser — this page describes the setup, it is not a compliance certification.
Payments and card data
Docketlane never sees or stores card numbers. Paid billing is not switched on yet. When it is, card details will be handled by the payment provider and will not pass through our database.
The payment records inside the app are something different: they are notes you keep about money a client has paid you — an amount, a date, and a label such as "bank transfer" or "card". That label is just a word describing how you were paid. No card number, expiry or CVV is stored anywhere in Docketlane.
Signing in
You can sign in with an email address and password, or with a one-time link sent to your email. Authentication is handled by Supabase Auth; we do not implement our own password storage.
Shared quote links use a token that is stored only as a hash, so the link you send a client cannot be reconstructed from the database. Shared and private routes are also served with headers telling search engines not to index them.
Getting your data out, and deleting it
Your client list can be exported to CSV from the Clients page at any time. Invoices and quotes can be downloaded as PDFs.
Account deletion removes your records — invoices, quotes, clients, notes, follow-ups and activity history — through a single database routine, so nothing is left behind in a table someone forgot about. Deletion is permanent and is not recoverable by us.
In transit
The site is served only over HTTPS and sends a long-lived HSTS header, so browsers refuse to connect over plain HTTP after their first visit. Responses also carry `X-Content-Type-Options`, `X-Frame-Options`, `Referrer-Policy` and a restrictive `Permissions-Policy` that turns off camera, microphone, geolocation and payment APIs, none of which the app uses.
We have not yet deployed a Content-Security-Policy. A policy that has not been properly exercised against every part of the app tends to break things rather than protect them, so it is queued as deliberate work rather than shipped half-tested. We would rather tell you that than imply a control we do not have.
Reporting a vulnerability
If you have found a security problem, please report it privately to security@docketlane.com.au and give us a reasonable period to fix it before disclosing it publicly. Machine-readable contact details are published at /.well-known/security.txt.
Please do not access, modify or extract data belonging to other users while testing. If you need an account to demonstrate an issue, use your own.
- We will acknowledge a report and tell you whether we can reproduce it.
- We will tell you when it is fixed.
- We do not currently run a paid bug bounty.
What this page is not
Docketlane is an independent Australian product. It is not affiliated with, endorsed by, approved by or certified by the Australian Taxation Office or any government agency, and nothing here is a compliance certification.
If your business has obligations that depend on where data is stored or how it is retained, check with your own adviser rather than relying on this page. Questions are welcome at our contact page.