VaultFlow: Contracts, Milestones and Files for a Freelancer Who Wants to Host It Themselves
A freelancer's working papers are contracts, files that clients send and receive, and a schedule of what is owed when. VaultFlow puts those three things in one self-hosted app. The README describes it as a privacy-first, offline-enabled platform that runs on your own infrastructure, with no third-party analytics.
What it does
Contracts can be created, tracked and signed from milestone-based templates. Payment milestones tie a schedule to contract deliverables. File sharing encrypts files with AES-256 and uses client-side key derivation. A client portal lets a client review a contract, download files and see payment status. Nodemailer sends notifications for contracts, payments and shares.
The stack and the hardening
The front end is React 18 with TypeScript and Vite, using React Hook Form and TanStack Query. The back end is Express with TypeScript, Prisma and a file-based SQLite database. The README lists JWT authentication with bcrypt and HTTP-only cookies, Helmet security headers, API rate limiting, Multer upload handling with type and size limits, and input validation with express-validator and Zod. Docker Compose starts the stack with one command.
A note on what encryption covers
The architecture diagram in the README says the database is encrypted at rest via filesystem permissions. That is access control on the host, not database-level encryption, and I want that distinction visible. The AES-256 claim applies to shared files. If your threat model includes someone with disk access, you need full-disk encryption on the machine that hosts the SQLite file.
The environment example also ships placeholder secrets for the JWT and encryption keys. They are marked as values to change before production, and they should be.
Same bet as my other local-first tools
KeepTrak keeps invoices local. Varsha keeps family documents on your device. VaultFlow applies the same idea to the client relationship: your contracts and files live where you put them, and the only party with a copy is the party you send it to.
Sources
VaultFlow README: github.com/yethikrishna/vaultflow.