Security
Built for sensitive records.
How TatDraft protects the IDs, health answers and signatures your studio collects.
Private storage
Waiver PDFs, ID photos, selfies and signatures are stored in a private bucket. Files open only through signed links that expire after five minutes.
Studio isolation
Row-level security in the database restricts every record and file to members of the studio that owns it. Studios can never see each other’s data.
Restricted kiosk sessions
A kiosk runs on a random 256-bit token. Only its SHA-256 hash is stored. The token can load your artists and consent settings and submit new waivers, nothing more. Sessions expire after 12 hours and can be revoked at any time.
Owner exit PIN
Leaving kiosk mode requires the studio’s Owner Exit PIN. It’s verified on the server and stored only as a salted PBKDF2-SHA256 hash (210,000 iterations), never as the raw PIN. Five wrong attempts locks the session.
Owner sign-out
Your owner login is signed out of the tablet before it’s handed to clients, and a kiosk clears a client’s details if they walk away mid-form.
Encryption in transit
Every page and API call is served over HTTPS with HSTS. Billing is handled entirely by Stripe; TatDraft never sees card numbers.
TatDraft provides configurable tools. Consent wording and retention requirements vary by jurisdiction, so studios should review their forms with qualified counsel.