Compliance & Security

Credible Documents is built with security and compliance at its core. Here's a transparent overview of our current compliance posture and roadmap.

Compliance Status

✓ Active

ESIGN Act

Electronic signatures created through our platform are legally binding under the US Electronic Signatures in Global and National Commerce Act (15 U.S.C. § 7001).

✓ Active

UETA

Compliant with the Uniform Electronic Transactions Act as adopted in 47 US states. Our audit trail meets all UETA requirements for enforceable electronic signatures.

✓ Active

eIDAS (Simple)

Our electronic signatures qualify as Simple Electronic Signatures (SES) under EU Regulation 910/2014. Valid for most commercial and personal agreements in the EU.

✓ Active

GDPR

We have implemented GDPR-required technical and organizational measures. A Data Processing Agreement (DPA) is available for EU customers. Data subject rights are supported.

⚡ Controls Active

HIPAA

Technical safeguards consistent with HIPAA requirements are implemented (encryption, audit logs, access controls). Formal HIPAA certification and BAA are on our roadmap.

⚡ Controls Active

CCPA

California Consumer Privacy Act rights are supported. We do not sell personal data. Data subject access and deletion requests are honored within 30 days.

→ Planned

SOC 2 Type II

Independent security audit certification is on our product roadmap. Our existing controls align with SOC 2 Trust Service Criteria.

→ Planned

HIPAA Certification

Full HIPAA certification with Business Associate Agreement (BAA) is planned. Contact us if you require a BAA for your use case.

→ Planned

EU Data Residency

EU-based data storage option is on our roadmap, allowing EU customers to keep data within the European Union.

Security Controls

🔐

Encryption

AES-256 encryption at rest. TLS 1.2+ for all data in transit. Bcrypt password hashing. No plaintext secrets.

🔑

Access Control

Two-factor authentication (2FA) for all accounts. API key management with rate limiting. Tiered permissions per subscription plan.

📋

Audit Logging

Comprehensive audit trail for all document actions including uploads, edits, signing events, and access. Exportable as PDF.

🦠

Malware Prevention

ClamAV virus scanning on all uploaded files. Daily virus definition updates. Infected files are rejected and deleted.

⛓️

Blockchain Integrity

Document hashes recorded on Hyperledger Fabric private blockchain. Immutable proof of existence and authenticity. Tamper detection on verification.

💾

Backup & Recovery

Automated daily database backups with 10-day retention. Email confirmation on each backup. Monthly secret key rotation.

🛡️

Attack Prevention

CSRF protection on all forms. Rate limiting and account lockout after failed login attempts. IP-based brute force protection.

⏱️

Session Management

Automatic session timeout (7 days for customers, 30 minutes for admins). Secure session cookies. Device trust management.

Electronic Signature Compliance

Every signature created through Credible Documents captures the following for legal enforceability:

Identity
Name + email address verification
Intent
Affirmative confirmation to sign electronically
Timestamp
UTC timestamp of signing event
IP Address
Signer's IP address recorded
Device
Browser and OS fingerprint
Document Hash
SHA-256 hash before and after signing

Compliance Documents

Need compliance documentation?

For enterprise compliance reviews, security questionnaires, or signed DPA documents, contact our team.

Contact Enterprise Team →