S summary.To
Security

Your clients trust you.
You can trust us.

Every file, every request, every booking on summary.to is protected by encryption and kept private — only you can see what clients send you.

🔒
DPDP-ready
India's Digital Personal Data Protection Act 2023
🛡️
End-to-end encrypted
TLS in transit · AES-256 at rest
🔐
Zero data selling
We never sell client or expert data to third parties
🌏
Singapore data residency
Closest AWS / Cloudflare region to India
🔑

Encryption everywhere

All data transferred between clients, experts, and our servers uses TLS 1.3. Files stored in Cloudflare R2 are encrypted at rest with AES-256. Nobody — not even our team — can read your files without your session token.

👁️

Access controls

Only you can access requests sent to your profile. Clients can't see each other. Our team cannot access your inbox without an explicit support request that you initiate. Each download link is time-limited (1 hour) and tied to your account.

🇮🇳

DPDP alignment

summary.to is built in alignment with India's Digital Personal Data Protection Act 2023. Clients provide explicit consent before uploading. You can request deletion of your data at any time by writing to us.

🏗️

Secure infrastructure

We run on Cloudflare R2 (object storage), Neon PostgreSQL (database), and Railway (compute) — all enterprise-grade platforms with their own SOC 2 and ISO certifications. No self-managed servers.

🧑‍💻

Authentication

Expert accounts are protected by Clerk — a dedicated authentication provider with MFA support, session management, and brute-force protection built in. We never store passwords.

📋

Data retention

Client uploads and request details are retained to allow you to review and respond. You can delete any request from your inbox at any time. We do not keep data beyond what is needed for the service.

Transparency

We earn trust through openness.

We publish our system status publicly and communicate clearly whenever issues arise. Our goal is to give experts and clients confidence in how their data is handled.

View status page → Privacy policy → Contact security →

Found a security issue?

We take responsible disclosure seriously. If you've found a vulnerability, please tell us before going public — we'll acknowledge it and fix it fast.

Report a vulnerability →