Security & data handling

Security controls for organizations handling sensitive information.

We treat your agreements the way a good IT partner should — privately, carefully, and with a clear trail of who did what. Below is what the platform does today, stated only where we can substantiate it.

Platform security

  • Documents are private by default — there are no public document URLs.
  • Recipient signing links are single-purpose, random, and expire; only a hash of each token is stored.
  • CSRF protection (double-submit token) guards state-changing requests.
  • Rate limiting protects authentication and signing endpoints from brute force.

Encryption

  • Documents are encrypted at rest using envelope encryption before they are written to storage.
  • Traffic is served over HTTPS/TLS in production.
  • Passwords are hashed with bcrypt; session and one-time tokens are stored only as SHA-256 hashes, never in plaintext.

Access controls

  • Every workspace is an isolation boundary — queries are always scoped to the workspace, with no implicit cross-workspace access.
  • Role-based access (owner, admin, member, viewer) is enforced on the server, not just hidden in the UI.
  • Recipients can access only the specific document assigned to them, via their own token.

Audit trails

  • An append-only audit trail records document creation, sending, views, consent, signatures, completion, downloads, and voids.
  • Each event captures timestamp, actor, IP address, and device — never document contents or signature images.
  • A completion certificate is appended to each finished PDF, and original content is hashed as a tamper baseline.

Data handling & retention

  • We store only the metadata needed to operate the service and produce a defensible signing record.
  • Analytics events are privacy-conscious and never include document content, form values, signing tokens, or recipient PII.
  • Documents are kept until you delete them. Workspace owners can choose a retention period in settings; automatic deletion under that setting is not active yet.

Backups & availability

  • The database and document storage are backed up nightly to a separate disk and kept for 14 days. Document files stay encrypted inside the backups, and restores are tested.
  • Uptime and application health are monitored continuously. We don’t publish a formal availability SLA.

Healthcare workflow considerations

Tarchos Sign is being designed with administrative and technical safeguards that can support organizations handling sensitive information. HIPAA compliance depends on the configuration and practices of both Tarchos and the customer. Contact us to discuss security requirements and BAA availability.

Shared responsibility

Even with a strong platform and a signed BAA, your organization remains responsible for who you grant access to, what information you place in documents, your risk analysis, and your policies. We do not claim to be “HIPAA certified,” “HIPAA approved,” or “fully HIPAA compliant.”

Where your data is processed

Tarchos Sign runs on infrastructure in the United States. Documents, accounts, audit records and backups are processed and stored there. If you use Tarchos Sign from another country, your data is transferred to the United States.

We do not offer hosting in the European Union or any other region, we hold no third-party security certifications, and we do not claim GDPR, UK GDPR or eIDAS compliance. Tarchos Sign provides simple electronic signatures — not certificate-based, advanced or qualified signatures. Requirements differ by country and document type, so check what applies to your documents. Questions about privacy or data handling: [email protected].

Responsible disclosure

Found a potential vulnerability? Email [email protected] with the details. We appreciate reports made in good faith and will acknowledge them. Please give us a reasonable window to respond before any public disclosure.

Frequently asked questions

Do you offer a Business Associate Agreement (BAA)?
BAAs may be available for eligible accounts following security, plan, and legal review. A BAA is required before any protected health information is handled on your behalf. Contact us to begin.
How do I report a security issue?
Please email [email protected] with details. We welcome responsible disclosure and will acknowledge reports. Please do not publicly disclose an issue before we have had a chance to respond.

This page is informational and is not legal advice. Security capabilities evolve; for the specifics that apply to your account, see our Terms and Privacy Policy or contact us.

Have security requirements to discuss?

Start free, then reach out about security, retention, and BAA availability for your organization.