Skip to content
In a bitSignIn a bit sign

Security and trust

Security you can hand to your COLP

Written for someone doing due diligence rather than browsing. If something you need is not here, ask us and we will answer plainly.

Encryption

  • Documents and metadata are encrypted in transit using TLS.
  • Documents are encrypted at rest in storage.
  • Encryption keys are managed by our hosting provider's managed key service and are not held alongside the data.

Email notifications

  • Signers receive an invitation email containing a secure link to their document, plus reminders while it is outstanding.
  • You are notified by email when a document is opened and when it is signed.
  • The completed document and audit trail are emailed to all parties once signing finishes.

Audit trail and tamper-evidence

  • Every document carries an audit trail recording who signed, when, the email address used, the IP address, and the document version at the time of signing.
  • The completed document is hashed so any later alteration can be detected.
  • The audit trail can be downloaded at any time as a PDF.

Access controls

  • Access to your account is limited to the users you invite.
  • Passwords are stored hashed, and sessions expire.
  • Our own staff access to customer data is restricted, logged and used only to support you.

Retention and deletion

  • You choose how long completed documents are retained in your account.
  • You can delete a document at any time, and export before you do.
  • On account closure, data is deleted within the period set out in our DPA.

Questions from your COLP or IT provider?

Send them over and we will answer in writing.