DELIBERATE BY DESIGN

A clear view of your data.

What Hookjail does with the webhooks you send through it, what it cannot do yet, and where the limits are.

What is stored

  • The request body and allowlisted headers, encrypted, in private object storage. Never in the database, never indexed.
  • In the database only metadata (provider, event ID and type, size, status, timings) and a redacted preview.
  • Never stored: Authorization, cookies, API-key headers and URL query strings.
  • Logs contain counters only (codes and numbers); no URLs, tokens, addresses or payloads.

Encryption and keys

Each workspace has its own data key. Bodies, receiving URLs and signing secrets are encrypted with AES-256-GCM, bound to the record they belong to so a stored value cannot be swapped for another. Data keys are wrapped by a master key with a version number, so keys can be rotated. Deleting a workspace destroys its key first, which makes its stored payloads unreadable immediately.

Today, master keys live in Cloudflare Worker secrets.

Moving them to a dedicated key-management service is planned. Until then, anyone with permission to deploy or read secrets for Hookjail’s Cloudflare account could technically read customer data. We do not claim that Hookjail cannot read your payloads.

Who can see payloads

Only signed-in members of your workspace, and only through Reveal payload, which needs a written reason, is rate-limited, is recorded in an append-only audit log before the data is returned, and closes itself after five minutes. Previews and search never need the original.

Retention and deletion

You choose how long originals and delivery records are kept, within your plan. A scheduled job deletes expired originals from storage and then clears their pointers; deleted endpoints and workspaces are purged the same way. Temporary webhooks are closed after 30 minutes and deleted by a timer with a scheduled sweep as backup.

Database backups and point-in-time recovery may hold deleted metadata for a limited time after deletion. Raw payloads are not in the database.

Outbound requests

You choose where deliveries are forwarded, so Hookjail restricts it: HTTPS on port 443 to public hostnames only; IP addresses, internal and wildcard-DNS names refused; the resolved address must be public; redirects are not followed; responses are size-limited. A destination cannot point back at Hookjail.

Accounts and isolation

Sign-in uses one-time e-mail links: no passwords exist to leak. A link works once, in the browser that requested it, for ten minutes. Sessions use host-only, HTTP-only cookies. Every record belongs to a workspace and every query is scoped to it; an automated test suite checks that one workspace cannot read, change or learn about another’s resources.

Sub-processors

  • Cloudflare: hosting, storage, database, networking.
  • Resend: sign-in and alert e-mails (addresses and message text; never payloads).
  • Polar: payments, when paid plans open.

What we do not claim

  • No independent security audit or certification yet.
  • No customer-managed keys, SSO or data-residency choice yet.
  • Exactly-once delivery: a timeout can hide a request your app already handled. Make handlers idempotent.

Do not send regulated data you are not allowed to share with a processor. Sending full card numbers is prohibited.