Data encryption

Encrypted at every step

Your record, your documents and your vault are encrypted on the way to us, while they are stored, and again in every backup.

Layer by layer

Each layer guards against a different risk, so no single lock is doing all the work.

On the way
Every connection uses HTTPS with modern TLS. Older, weaker protocols are refused.
While stored
Your record, your signed documents and your pages are encrypted at rest with AES-256.
Your vault, twice
Vault files are encrypted by our own code with AES-256-GCM before they are stored, then encrypted again at rest.
In every backup
Off-site backups are encrypted before they leave, and the backup provider cannot read them.
Passwords
Passwords are salted and hashed 100,000 times. We never store them and cannot read them.
Keys kept apart
Encryption keys live in a separate secret store, never beside the data they protect.

How the layers fit together

Your document sits inside every layer at once.

On your device
Your connection is encrypted before anything leaves your phone or computer.
In our app
Vault files are encrypted by our own code, with a key only the app holds.
In storage
Everything written to disk is encrypted by the storage itself.
In backup
A second copy is kept with another provider, already encrypted, with a key that provider never sees.
At sign-in
You are signed out after 30 minutes idle, and sign-in cookies only work on our site.
Share links, fingerprinted
The links you share are stored only as fingerprints, so even a copy of our database could not open them.

Strong by default

AES-256

Everything stored

Your record, your documents, your vault and every backup.

100,000

Hashing rounds

Salted and hashed, so we never store your password and cannot read it.

2

Vault layers

Encrypted by our own code, then again by the storage it sits in.

Your documents, locked down

Every plan gets the same protection, from the first document you upload.