Security
Security & Privacy
What we actually do to protect what you send.
Private customer files
Uploads go to private storage. There are no public links, and files are readable only by the account that sent them.
Account-level access controls
Every case, submission, draft and outcome is tied to your account and enforced by database access rules, not just by the app screens.
Server-side AI processing
Analysis and draft preparation run on our servers. Provider credentials are never present in your browser.
Sensitive text masking
Sensitive values FixIt can detect in text are masked before analysis. PDF text is extracted and masked. Photos need your permission because automatic image masking isn’t available yet.
Database isolation between customers
Access rules are applied per row, so one account cannot read, change or delete another account’s data. We test this with separate accounts.
Customer-controlled deletion
You can delete a case, or your whole account, from inside FixIt.
Payments
Card details are entered on our payment provider’s form. FixIt never stores card numbers or security codes.
What we don’t claim
FixIt holds no security certifications, and we don’t claim SOC 2 or any similar audit. We’d rather tell you exactly what we do. Questions or a concern to raise? Use Report a problem.