Skip to content

Security

Last updated 2026-08-08

How Signatas protects your documents and the evidence attached to them. We describe what we do in plain terms and avoid claiming more than we can show.

Tamper-evident, and what that means

We do not claim your records cannot be altered — nothing can promise that. We claim something narrower and provable: if a sealed record is altered, verification detects it. Every ceremony builds a hash chain, and the signed PDF carries a cryptographic signature over its exact bytes, so a single changed byte is visible to anyone who checks.

You can verify a Signatas record without us. The evidence format is published, and the check can be run with standard tools — which is the point. Evidence you can only verify through the company that produced it is not independent evidence.

Isolation between customers

Every row of your data is fenced off at the database level, and that fence is enforced by the database itself rather than by application code that could forget it. One customer cannot reach another's documents, signers or evidence.

Payments

Card payments are handled entirely by Stripe. Signatas never sees, stores or logs your card number — the payment form is Stripe's, not ours.

Reporting a problem

If you believe you have found a security issue, tell us at hello@signatas.com. We would much rather hear from you than not, and we will not pursue anyone acting in good faith to report a genuine vulnerability.