Summary: Contrax is a multi-tenant SaaS for post-signature renewal ops. This page is the security-review pack for procurement: data classes, subprocessors, access control, and what we do not claim.
Security review pack
Use this with trust & data processing and Enterprise SSO. Binding terms live in Terms and Licensing. Contrax does not claim a completed SOC 2 report on this page; artefacts are shared under NDA when available.
Data Contrax stores
- Contract metadata (parties, dates, notice periods, workflow, notice proof hashes)
- Uploaded PDFs/DOCX you choose to ingest
- Integration secrets you save (webhooks, ERP tokens) — workspace-admin only
- Audit export rows (workflow, portal, extraction review, approvals)
Controls
- TLS in transit; Postgres at rest on the hosted database provider
- Clerk authentication; Enterprise SSO enforcement for SAML/OIDC IdP logins
- Role-based access (admin / member / viewer) on tenant APIs
- Audit export v2 (CSV/JSON) on Enterprise
- Optional webhook HMAC (`X-Contrax-Signature`)
Subprocessors (typical production)
- Vercel — application hosting
- Clerk — authentication and Enterprise SSO connections
- Prisma Postgres (or your configured DATABASE_URL host) — primary data
- Resend — transactional email
- Stripe — billing
- Anthropic — vendor extraction when you run an analysis pass
- Inngest — scheduled jobs (reminders, ETL, warehouse export)
What Contrax will not do
- Email opt-out notices to your vendors
- Act as legal counsel or a CLM authoring suite
- Invent G2 ratings or SOC 2 certification dates
Enterprise support: in-app priority ticket (4-hour first-response target, Europe/Paris business hours) or sales@usecontrax.com. Status: /status.