Your renewal data, kept private.
Resubly tracks contracts for small Finance and Ops teams without monitoring anyone or reaching into their devices. Everything on this page is how the product works today, not a roadmap.
Scoped access
Every workspace sits behind authenticated sessions and role-based membership. Server-side checks run before any organization, billing, or subscription record is returned. Owners control billing; viewers cannot reach settings.
Encrypted, backed up
Data is encrypted with TLS 1.2+ in transit and at rest on our managed database and storage (Convex). Backups run automatically. Passwords are hashed and sessions are managed by Better Auth.
Private by design
Read-only renewal intelligence. No device agents, no employee surveillance, no data resale, and no advertising trackers inside the app. Your contract content is never used to train AI models.
What happens to your data
While active
Subscriptions, documents, and renewal history are kept so your audit trail stays complete. Delete any subscription or document yourself, anytime.
When you ask to delete
Organization deletion starts a 30-day grace period. You can reverse it and recover everything, which protects against mistakes.
After the grace period
A hard purge: subscriptions, documents and their stored files, history, memberships, and orphaned accounts. Gone, not flagged. Billing records are held only as long as tax rules require.
Who we work with
The complete list of services that touch customer data.
Controls in the product
- Every account must verify its email address before it gets a session or any workspace access.
- Roles are enforced server-side, down to department level. A department viewer cannot read another department's subscriptions, from the UI or the API.
- Payment webhooks are verified with HMAC signatures and a replay window before anything is written.
- Outbound Slack and Teams notifications only ever post to https webhook URLs on the providers' own domains; private addresses are rejected.
- Public forms (contact, waitlist, signup) are rate limited so they cannot be used to spam or scrape.
- The site ships strict security headers: HSTS with preload, a content security policy, and frame embedding disabled.
On certifications, plainly
Resubly is not SOC 2 certified yet. This page is a plain description of what the product actually does, not a compliance badge. If you have a vendor questionnaire or a security review, email hello@resubly.com and we will answer it directly.