Data encryption
Encrypted at every step
Your record, your documents and your vault are encrypted on the way to us, while they are stored, and again in every backup.
Layer by layer
Each layer guards against a different risk, so no single lock is doing all the work.
- On the way
- Every connection uses HTTPS with modern TLS. Older, weaker protocols are refused.
- While stored
- Your record, your signed documents and your pages are encrypted at rest with AES-256.
- Your vault, twice
- Vault files are encrypted by our own code with AES-256-GCM before they are stored, then encrypted again at rest.
- In every backup
- Off-site backups are encrypted before they leave, and the backup provider cannot read them.
- Passwords
- Passwords are salted and hashed 100,000 times. We never store them and cannot read them.
- Keys kept apart
- Encryption keys live in a separate secret store, never beside the data they protect.
How the layers fit together
Your document sits inside every layer at once.
- On your device
- Your connection is encrypted before anything leaves your phone or computer.
- In our app
- Vault files are encrypted by our own code, with a key only the app holds.
- In storage
- Everything written to disk is encrypted by the storage itself.
- In backup
- A second copy is kept with another provider, already encrypted, with a key that provider never sees.
- At sign-in
- You are signed out after 30 minutes idle, and sign-in cookies only work on our site.
- Share links, fingerprinted
- The links you share are stored only as fingerprints, so even a copy of our database could not open them.
Strong by default
AES-256
Everything stored
Your record, your documents, your vault and every backup.
100,000
Hashing rounds
Salted and hashed, so we never store your password and cannot read it.
2
Vault layers
Encrypted by our own code, then again by the storage it sits in.
Your documents, locked down
Every plan gets the same protection, from the first document you upload.