Security

YOUR DOCUMENTS DESERVE SERIOUS PROTECTION

This page describes protections that are actually implemented. We do not claim certifications or compliance frameworks we have not completed.

Secure transmission

Every page and every upload is served over HTTPS. Files move directly from your browser into private storage over an encrypted connection. Documents are never sent as ordinary email attachments.

Private storage

Uploaded documents live in a private storage bucket. There is no public URL for your file, no directory listing, and nothing for a search engine to crawl. Access requires an authenticated, authorized request, and links generated for viewing are short-lived and expire.

Access controls

  • Database-level row security so one customer can never read another customer's records
  • Role-based access separating customers, notaries, and administrators
  • Administrative areas that are not publicly reachable and are excluded from search indexing
  • Internal notes and staff-only fields that are never exposed to customer accounts

Upload validation

Uploads are restricted by file type (PDF, DOC, DOCX, JPG, PNG) and by size, with a 25 MB per-file limit enforced both in the browser and at the storage layer.

Access logging and retention

Request activity is recorded so we can see what happened to a request and when. Documents are retained for the period needed to complete the service and satisfy applicable recordkeeping requirements, then deleted under our retention controls.

Account security

Customer accounts use email verification and support sign-in with Google. Sessions are handled by our authentication provider rather than custom credential handling.

What we do not claim

We do not describe our service as HIPAA compliant, SOC 2 certified, bank-level, or military-grade. Those are specific claims that require specific audits and verification. If and when such verification exists, it will be stated here plainly.