Skip to main content

Trust Center

Security at Document.com

Your legal documents are some of the most sensitive things you own. Here is exactly how we protect them — stated plainly, and kept current.

256-bit TLS encryptionPowered by StripePCI DSS compliant checkoutESIGN & UETA compliantWe never sell your dataMonitored 24/7

Encryption everywhere

All traffic is encrypted in transit with TLS 1.2+, and your documents and data are encrypted at rest on our infrastructure. Strict transport security (HSTS) is enforced across every Document.com property.

Tamper-evident e-signatures

Every e-signature envelope carries a cryptographically hash-chained audit trail — signer identity, timestamps, IP addresses, and every event from send to completion — plus a signing certificate. Signatures completed on Document.com are legally binding under the U.S. ESIGN Act (15 U.S.C. §7001 et seq.) and UETA.

Your card never touches our servers

Payments are processed by Stripe, a PCI DSS Level 1 certified processor. Card details are entered directly into Stripe's secure fields and never pass through or get stored on Document.com systems.

We never sell your data

We do not sell, rent, or share your personal information or your documents with third parties for marketing. You can request account deletion at any time, and honor it we do — permanently.

Monitored around the clock

Independent synthetic checks probe every customer-facing surface of Document.com every 60 seconds, with automatic alerting to our engineering team. Availability and incidents are tracked continuously.

Hardened infrastructure

Production systems run on isolated cloud infrastructure with key-only SSH access, default-deny firewalls, intrusion lockout, automatic security patching, and least-privilege access controls, backed by written security and incident-response policies.

Your privacy rights

We honor access, correction, deletion, and do-not-sell requests for everyone, not just where the law requires it. See our Privacy Policy and Do Not Sell or Share My Personal Information. Data-handling questions: [email protected].

Responsible disclosure

If you believe you have found a security vulnerability in any Document.com service, we want to hear from you. Email [email protected] with the subject line "Security vulnerability report", including steps to reproduce and any relevant URLs. Our machine-readable policy lives at /.well-known/security.txt.

We commit to acknowledging reports within 2 business days and to keeping you informed as we investigate. We will not pursue legal action against good-faith research that respects user privacy, avoids service disruption, and gives us reasonable time to remediate before public disclosure. Please do not access data that is not yours — use test accounts wherever possible.