Security

Security & Privacy

What we actually do to protect what you send.

Private customer files

Uploads go to private storage. There are no public links, and files are readable only by the account that sent them.

Account-level access controls

Every case, submission, draft and outcome is tied to your account and enforced by database access rules, not just by the app screens.

Server-side AI processing

Analysis and draft preparation run on our servers. Provider credentials are never present in your browser.

Sensitive text masking

Sensitive values FixIt can detect in text are masked before analysis. PDF text is extracted and masked. Photos need your permission because automatic image masking isn’t available yet.

Database isolation between customers

Access rules are applied per row, so one account cannot read, change or delete another account’s data. We test this with separate accounts.

Customer-controlled deletion

You can delete a case, or your whole account, from inside FixIt.

Payments

Card details are entered on our payment provider’s form. FixIt never stores card numbers or security codes.

What we don’t claim

FixIt holds no security certifications, and we don’t claim SOC 2 or any similar audit. We’d rather tell you exactly what we do. Questions or a concern to raise? Use Report a problem.