Trust Center

Security you can audit.
Because we did — six times.

Notarization is a trust business. So we publish how we earn it: independent audit rounds, cryptographic document sealing, and monitoring that never sleeps.

6

security audit rounds

0

critical findings open

160+

test suites run nightly

100%

payments signature-verified

The audit trail

Six consecutive independent security audit rounds. Every finding remediated, most within the same working day.

Round 1
REMEDIATED

Session & Browser Security

  • Strict CORS allow-list
  • Instant session revocation on account lockout
  • HttpOnly / Secure / SameSite cookie flags across the platform
Round 2
REMEDIATED

Server-Side Request & Export Safety

  • SSRF guard on every outbound URL the platform fetches
  • CSV formula-injection protection on all data exports
Round 3
REMEDIATED

Payment Integrity

  • Stripe webhook origin verification
  • Cryptographic webhook signature enforcement
  • Every payment event re-verified directly with Stripe — forged events cannot mark an order paid
Round 4
REMEDIATED

Access Control

  • Escrow endpoints hardened against cross-account access (IDOR)
  • AI analysis results scoped strictly to their owners
Round 5
REMEDIATED

Field Tools & Audit Trails

  • Authentication enforced on field scanner and verification tools
  • Audit log retention policies corrected and locked
Round 6
PASSED

Full-Platform Re-Audit

  • Zero critical or high findings across auth, payments, admin, uploads and public endpoints
  • Two minor hardening notes (email escaping, query sanitization) fixed the same day

Defense in depth

Security isn't a checkbox — it's layered into every ceremony, seal and payment.

X.509 Digital Sealing

Every notarized PDF is sealed with a real IdenTrust X.509 certificate. Alter one byte and the seal breaks — verifiable in any PDF reader.

Blockchain Anchoring

Document hashes are anchored to Hedera Hashgraph, creating an immutable public timestamp no one — including us — can rewrite.

Passkeys & Magic Links

Phishing-resistant WebAuthn passkeys and single-use magic links. Passwords are bcrypt-hashed and never stored in plain text.

Automatic Threat Blocking

Brute-force attempts trigger account lockouts, automatic IP bans, per-endpoint rate limits and admin alert digests.

Live Ceremony Monitoring

Vision-AI watches every notarization ceremony for deepfakes, face swaps, screen replays and coercion in real time.

24/7 Payment Monitoring

Every payment webhook is signature-verified, logged and monitored. A failure streak alerts administrators within minutes.

Nightly Regression Testing

The full automated test suite (160+ suites) runs every night. Administrators receive a pass/fail digest before breakfast.

Least-Privilege Admin

Every administrative endpoint enforces role checks, verified line-by-line in independent audit rounds.

Compliance program

Florida RON — Ch. 117

Built for Florida Statute 117.295 remote online notarization: identity verification, ceremony recording, journal retention and parcel verification.

IdenTrust Certificate Authority

Document seals chain to IdenTrust, a WebTrust-audited certificate authority trusted by US federal agencies.

SOC 2 Preparation

Controls, audit trails and monitoring are being aligned to SOC 2 Trust Service Criteria as we head into formal certification.

Independent Security Audits

Six consecutive audit rounds with every finding remediated — most within the same working day.

Found something? Tell us first.

We welcome responsible disclosure from security researchers. Report a vulnerability and we'll acknowledge within one business day.