EazyWaiver is built with security-first principles. Here's exactly how we protect your business data.
All sensitive tokens encrypted using AES-256 (Fernet)
All traffic secured with TLS 1.2+ end-to-end
We never store your QuickBooks password
Every action on your data is logged and reviewable
EazyWaiver uses industry-standard encryption at every layer. Your QuickBooks OAuth tokens are encrypted at rest using AES-256 symmetric encryption (Fernet). Passwords are hashed with bcrypt and are never stored in plain text or recoverable form.
Optional TOTP-based 2FA using any authenticator app (Google Authenticator, Authy, etc.). Strongly recommended for all accounts.
Sessions use signed, tamper-proof cookies. Browser sessions auto-expire on tab close, with a 15-minute inactivity timeout.
Multi-user organizations with owner, admin, and member roles. Each role has scoped permissions to prevent unauthorized actions.
Time-limited, one-use password reset links (1-hour expiry) delivered to your verified email address only.
Our QuickBooks Online integration is built on Intuit's official OAuth 2.0 flow — the same standard used by major financial applications. We never see, store, or transmit your QuickBooks username or password.
EazyWaiver runs on enterprise-grade cloud infrastructure with redundant PostgreSQL databases, automated backups, and continuous uptime monitoring.
Every meaningful action on your data — waiver generation, sending, signing, deletion, team changes — is recorded in a tamper-evident audit log. You can view your full activity history at any time from your dashboard.
Access your audit log from Dashboard → Activity Log or the avatar menu.
You own your data. EazyWaiver respects your right to access, export, and delete your information at any time, in accordance with applicable privacy laws.
Download a complete copy of all your account data, waivers, and profile information at any time from your Profile page.
Request permanent deletion of your account and all associated data. Requests are processed within 30 days.
Update or correct your profile information at any time from your Profile settings page.
To exercise these rights, log in and visit your Profile page, or contact us at privacy@eazywaiver.net.
We take security vulnerabilities seriously. If you discover a security issue in EazyWaiver, please report it responsibly before public disclosure so we can address it promptly.
Send vulnerability reports to security@eazywaiver.net. Please include a clear description, reproduction steps, and the potential impact. We aim to acknowledge all reports within 48 hours and will keep you informed as we work on a fix.
We do not pursue legal action against security researchers who act in good faith and follow responsible disclosure practices.
Our team is happy to answer any questions about how we protect your data. Reach out anytime.
Contact Security Team