CMConsentMuster NZBack to website
SECURITY

Security overview

Consent files can be commercially and personally sensitive. ConsentMuster keeps each signed-in property record private by default.

Last updated 5 August 2026

Identity and project access

Requests are tied to the signed-in account. Every project operation checks ownership or recorded team membership. Owners and admins control invitations; viewers cannot change the record.

Invitations are matched to the invited email when that person signs in. Activity events record important project changes.

Files and data

Uploaded documents use private object storage and are accessed through authorised application routes rather than public file URLs. Project records use a private database. File extension, declared type, internal signature, size and duplicate-content checks reduce accidental and malicious uploads.

Exports are generated only after an account or project access check. Users can remove individual files, projects and their account. Payment card data is not collected by ConsentMuster; configured checkout is hosted by the payment provider.

Automated processing and secrets

Document-analysis, payment and transactional-email credentials are supplied as server-side environment secrets and are not exposed to the browser. Automated analysis treats uploaded documents as untrusted input and requests structured outputs.

Operational safeguards include per-user plan limits, global processing safety limits, request throttling, access checks, private storage, file fingerprints, activity records, dependency maintenance, incident handling and periodic review. No internet service can promise absolute security, so users should upload only project information needed for the workflow.

Reporting a concern

If you believe a project has been accessed improperly, stop sharing the record and contact the site owner promptly with the affected project and approximate time. Avoid sending sensitive files in the initial report.

Questions, privacy requests and security concerns can be sent to hello@consentmuster.co.nz or raised through the ConsentMuster website contact form. Do not include sensitive project files in the first message.

Email ConsentMusterOpen contact form