Security & trust
Your content. Your customers’ privacy. Your data to take with you.
ItemDocs runs the infrastructure. You own everything on it.
Nothing public before publish
Drafts, hidden modules and unpublished products are private. Draft pages show a neutral holding page.
Every upload validated
File type is verified by content, not extension. Size limits, image re-encoding and rate limits protect every plan.
Tenant isolation
Every query is scoped to your organisation. Roles (owner, admin, editor, viewer) are built into the permission model.
Encrypted everywhere
HTTPS for every page and asset, strict security headers, hashed session tokens and scrypt-hashed passwords.
You own the data
Export products, IDs and content at any time. Delete content or your whole organisation from Settings.
Privacy by default
Customers never need an account. Analytics use daily-rotating hashes and country-level aggregation — no personal data is stored.
What we store about customers
Aggregate page opens, QR scans, content views and search terms by country and device type. No accounts, no cookies required to read a page. If a customer chooses to register a product, the details they enter go to that manufacturer.
Search terms
What customers type into a product page is kept so manufacturers can fill content gaps. It is never linked to a person.
Larger teams
Custom contracts and answers to security and procurement questionnaires on request. Every plan already includes team roles and an activity log.