VAULT 01Security
Security
Fillall is built for people who file forms on behalf of others — which means other people's personal data. The design principle is simple: hold as little as possible, for as short a time as possible.
Your rows never touch our database
Spreadsheet cell values (names, IDs, amounts) are processed row-by-row in memory and written only to encrypted object storage in your region. Our database stores job metadata — counts, ids, timestamps — never the data being filled. Error logs record which field failed, never the value that failed.
Automatic deletion, verified
Generated outputs and uploaded sheets are deleted automatically after your plan's retention window (24 hours on the founding/free tier). This is not a policy promise — the deletion sweep runs hourly and we test it end-to-end.
Regional isolation
Customer data lives in the region chosen at sign-up and is processed there. Regions share no customer data; cross-region moves are a deliberate, supported migration — never automatic.
Encryption
TLS everywhere in transit. Object storage is encrypted at rest; service credentials are stored AES-256-GCM encrypted. Passwords are hashed with a modern KDF; admin access requires a separate credential system with optional TOTP.
Reporting a vulnerability
Found something? Write to support@fillall.io with "Security" in the subject. A person reads it, fast; we won't take legal action against good-faith research.
