Your clients trust you.
You can trust us.
Every file, every request, every booking on summary.to is protected by encryption and kept private — only you can see what clients send you.
Encryption everywhere
All data transferred between clients, experts, and our servers uses TLS 1.3. Files stored in Cloudflare R2 are encrypted at rest with AES-256. Nobody — not even our team — can read your files without your session token.
Access controls
Only you can access requests sent to your profile. Clients can't see each other. Our team cannot access your inbox without an explicit support request that you initiate. Each download link is time-limited (1 hour) and tied to your account.
DPDP alignment
summary.to is built in alignment with India's Digital Personal Data Protection Act 2023. Clients provide explicit consent before uploading. You can request deletion of your data at any time by writing to us.
Secure infrastructure
We run on Cloudflare R2 (object storage), Neon PostgreSQL (database), and Railway (compute) — all enterprise-grade platforms with their own SOC 2 and ISO certifications. No self-managed servers.
Authentication
Expert accounts are protected by Clerk — a dedicated authentication provider with MFA support, session management, and brute-force protection built in. We never store passwords.
Data retention
Client uploads and request details are retained to allow you to review and respond. You can delete any request from your inbox at any time. We do not keep data beyond what is needed for the service.
We earn trust through openness.
We publish our system status publicly and communicate clearly whenever issues arise. Our goal is to give experts and clients confidence in how their data is handled.
Found a security issue?
We take responsible disclosure seriously. If you've found a vulnerability, please tell us before going public — we'll acknowledge it and fix it fast.
Report a vulnerability →