Security

Your money moves through us. It never sits with us.

You are about to run your quotes, your contracts, your invoices, and your bank data through a tool you did not write. That deserves a straight answer about how it is protected. Here is ours, without the marketing fog.

Built on rails you already trust

We run your money. We never hold it.

  • Card details never touch our serversEvery payment is taken on Stripe's own secure pages. We never see, store, or handle a card number.
  • Bank logins never touch our serversBank connections run through Plaid. You sign in with your bank, and we only ever receive read access to transactions.
  • Your money goes straight to your bankClient payments land in your account directly. We never hold your money, and we never sit between you and it.

Read how we protect your data

Payments

We never see a card number

There is no card entry form anywhere in The Contractor Codex. When your client pays, they pay on Stripe's own secure pages. The card goes from their browser to Stripe and never touches us.

  • Stripe is certified at the highest level in the payments industry, PCI Level 1. We lean on their certification rather than handling cards ourselves.
  • Money moves through Stripe Connect straight into your bank account. We never hold your client's funds.
  • Refunds, late fees, and payment plans all run through the same path, so there is no back door where a card would be handled differently.

Bank connections

We never see your bank login

When you connect a bank account so Codex can sort your costs onto jobs, you sign in on Plaid's screen, not ours. We receive a token that lets us read transactions, and nothing else.

  • Your bank username and password are never sent to us and never stored by us.
  • The connection is read-only. It can see transactions. It cannot move a dollar.
  • The access token is encrypted before it is stored, and you can disconnect a bank at any time from your settings.

Accounts and sign-in

Two-factor is required, not suggested

Sign-in is handled by Clerk, a dedicated authentication provider, so passwords are never stored in our own database.

  • Every account with admin access to a business must present a second factor. This is enforced by the app itself, not just recommended in a settings page.
  • The check covers the admin screens and the actions behind them, including bank linking, Stripe linking, and financial exports.
  • Client portal accounts are separated from admin accounts, and a client can only ever see their own projects, quotes, and invoices.

Your data

Locked in transit, and off the open internet

Traffic to the site is HTTPS only. Behind the scenes, the app talks to the database over an encrypted connection whose certificate is verified on every connect, so a stand-in server cannot quietly take its place.

  • The database does not sit on the public internet. It lives on a separate machine with no public address and a firewall that only accepts the app.
  • If the database certificate cannot be read, the database refuses to start rather than falling back to an unencrypted connection.
  • Each business's data is separated by design, and every action an assistant takes on your behalf is written to an audit log you can read.

Backups

The machine that writes the backup cannot read it

Backups run nightly and are encrypted before they ever leave the server. The key that decrypts them has never been on that server. It lives on encrypted drives held offline in two separate locations.

  • Backups are copied offsite to storage that is write-only from the server's side, so someone who took over the machine could neither read the history nor destroy it.
  • If encryption fails, the backup fails. It never quietly falls back to writing a readable copy.
  • The restore path has been tested end to end from an encrypted backup, not just assumed to work, and restore drills are scheduled to repeat.

How we operate

Separate keys, no shared logins

Access to the servers is split by job. The key that deploys the app cannot administer the database, and no machine holds a key that lets it push code back to the source repository.

  • There are no shared logins. Every access path is separate and can be revoked on its own.
  • Dependencies are checked automatically on every release, and a release is blocked if it carries a known high-severity issue.
  • Errors are monitored so problems surface quickly instead of sitting unnoticed.

Being straight with you

What we do not claim

Plenty of software companies put a wall of badges on this page. We would rather tell you where the line is.

  • We are not SOC 2 certified. We have not completed a SOC 2 audit or an ISO 27001 certification. If that is a hard requirement for you, we are not the right fit yet.
  • We have not had a third-party penetration test. Our security work has been done and documented in house, and reviewed against a written policy set.
  • We are a small independent company. The Contractor Codex is built and run by Bulwark Black LLC, not a large team with a dedicated security department. That is exactly why the money never sits with us and the backups are encrypted where we cannot undo it.

If any of this changes, we will say so here with a date on it.

Found a problem?

Tell us and we will act on it

If you believe you have found a security issue, we want to hear about it before anyone else does. We publish a security contact at /.well-known/security.txt and we answer it. You can also reach us through the contact form, and we will respond within one business day.

For how we collect, use, and delete your data, see the privacy policy.

Ready when you are

Try it with your own numbers

Every plan starts with a 30-day free trial, and nothing is charged until it ends.

See Pricing