Last updated: August 13, 2026

Security and confidentiality

How we protect the documents and data of non-resident founders.

1. Our commitment

Maera handles documents that define the legal and financial identity of our clients: passports, formation documents, EIN, contracts and bank statements. We treat every file with the same care we would our own: least-privilege access, encryption by default, and traceability of every action.

2. Encryption

Sensitive Vault documents are encrypted with AES-256-GCM. The key is derived from the client’s access passphrase using Argon2id and never leaves the browser in a reusable form: cryptographic keys are generated as non-extractable. In transit, all traffic uses TLS 1.2+. At rest, the database and file storage are encrypted by the infrastructure provider.

3. Data isolation between clients

Every record is protected at the database level with Row Level Security: a client’s query can only return rows that belong to them, even if the application had a bug. Partner portals operate on a separate data plane and only see the clients they manage themselves.

4. File access

We do not publish permanent document URLs. Every view or download generates a short-lived signed link, tied to the user who requested it, and expires automatically.

5. Team access

Internal access is role-based and limited to operational need. A team member only sees the information necessary to complete the contracted service. Administrative actions are logged with user, date and time.

6. Authentication

Sign-in with email and password or a social provider, passwords stored as hashes, sessions with expiration, and sign-out from all devices available from the profile. We recommend enabling verification with the associated email provider.

7. Monitoring and response

We run automated security and dependency scans on the platform continuously and review findings before every relevant deployment. If we detect an incident affecting personal data, we will notify affected clients by email with what we know, the estimated impact, and the actions taken.

8. Retention and deletion

We keep documents while the service relationship exists and for the period required by tax and registration obligations. Clients can request deletion of their account and files by writing to support@maera.com; we process requests within 30 days, except for information we must keep by law.

9. What we do NOT do

We do not sell data. We do not use client documents to train third-party models. We do not share information with third parties except for the providers necessary to deliver the service or when required by a competent authority.

10. Report a vulnerability

Write to support@maera.com with steps to reproduce it. Do not access others’ data, do not run denial-of-service tests, and give us a reasonable time to fix before publishing. We thank and credit those who report in good faith.

Final note

This document describes current controls and may be updated as the platform evolves. It does not constitute a certification or a guarantee that any system is invulnerable.

Contact

For security questions write to support@maera.com. For data deletion, contact support@maera.com.