Credible Documents is built with security and compliance at its core. Here's a transparent overview of our current compliance posture and roadmap.
Electronic signatures created through our platform are legally binding under the US Electronic Signatures in Global and National Commerce Act (15 U.S.C. § 7001).
Compliant with the Uniform Electronic Transactions Act as adopted in 47 US states. Our audit trail meets all UETA requirements for enforceable electronic signatures.
Our electronic signatures qualify as Simple Electronic Signatures (SES) under EU Regulation 910/2014. Valid for most commercial and personal agreements in the EU.
We have implemented GDPR-required technical and organizational measures. A Data Processing Agreement (DPA) is available for EU customers. Data subject rights are supported.
Technical safeguards consistent with HIPAA requirements are implemented (encryption, audit logs, access controls). Formal HIPAA certification and BAA are on our roadmap.
California Consumer Privacy Act rights are supported. We do not sell personal data. Data subject access and deletion requests are honored within 30 days.
Independent security audit certification is on our product roadmap. Our existing controls align with SOC 2 Trust Service Criteria.
Full HIPAA certification with Business Associate Agreement (BAA) is planned. Contact us if you require a BAA for your use case.
EU-based data storage option is on our roadmap, allowing EU customers to keep data within the European Union.
AES-256 encryption at rest. TLS 1.2+ for all data in transit. Bcrypt password hashing. No plaintext secrets.
Two-factor authentication (2FA) for all accounts. API key management with rate limiting. Tiered permissions per subscription plan.
Comprehensive audit trail for all document actions including uploads, edits, signing events, and access. Exportable as PDF.
ClamAV virus scanning on all uploaded files. Daily virus definition updates. Infected files are rejected and deleted.
Document hashes recorded on Hyperledger Fabric private blockchain. Immutable proof of existence and authenticity. Tamper detection on verification.
Automated daily database backups with 10-day retention. Email confirmation on each backup. Monthly secret key rotation.
CSRF protection on all forms. Rate limiting and account lockout after failed login attempts. IP-based brute force protection.
Automatic session timeout (7 days for customers, 30 minutes for admins). Secure session cookies. Device trust management.
Every signature created through Credible Documents captures the following for legal enforceability:
For enterprise compliance reviews, security questionnaires, or signed DPA documents, contact our team.
Contact Enterprise Team →