Trust & security

Last reviewed 22 August 2026

What we can prove, and what we won't claim.

A trust page that overstates itself is worse than none. Here is what the record proves, how your data is held, and the limits we state plainly — for you, and for the courts, registries and clients who will check what you seal.

The record

Content hash
A one-way fingerprint of the raw bytes, computed inside the verifier's own browser — the file never leaves their device.
Claim signature
A digital signature over each event's canonical record, one per event, tied to a published issuer key.
Chain
Each entry hashes its claim plus the previous entry hash. The head commits to all history.
QR token
A compact signed token binding the document to its issuer key — verifiable with no network at all.

Your data

  • Documents at rest — strong authenticated encryption, with a separate key for every workspace. We hold those keys as your processor, because we have to render, seal and deliver the files; this is not end-to-end encryption and we do not pretend it is.
  • Data residency (Firm) — document files and identity evidence can be stored on infrastructure restricted to the EU jurisdiction; service metadata (names, emails, fingerprints, the public record) is processed globally. Session recordings are captured by the video provider and moved into that storage afterwards, so the provider holds them briefly first.
  • Identity evidence — encrypted separately, visible only to the reviewing human, never embedded in any output document.
  • Verification — the public verify endpoint receives a 64-character digest and nothing else. No filename, no contents, no upload.
  • Ledger privacy — the public ledger page publishes integrity and keys, never per-entry signer names. Events surface only for a document you already hold.
  • Retention — documents, journal and evidence never expire on their own. Session recordings are deleted on the schedule you set, or kept until you delete them. Closing the account deletes everything except the public record, which holds fingerprints and signed claims, never files.

Honest limits

We are not a notary. The act is yours, under your commission. Whether it may be performed remotely, on camera, or for a given document is a question for your commissioning authority and your own judgement — we answer none of it, and nothing here is legal advice.

A seal is proof, not jurisdiction. It proves what was signed, by whom when identity was checked, and that nothing changed since. Whether that satisfies a given statute depends on your jurisdiction and use case.

We do not mint QES. No software can locally. We broker it through a qualified trust service provider and label it accurately everywhere.

Two levels below qualified, honestly named. Verified email for simple; a one-time code at signing plus cryptographic proof for advanced. We don't invent a fourth level to sound stronger.