Skip to content

Trust

Trust is built from evidence, not promises.

How your data is stored, how signatures are proven and which documents govern the service.

Processors

  • Supabase
  • Vercel
  • OpenAI
  • Google
  • Migadu
  • Paddle
  • Legal documents revision
  • billing terms

Four security facts

Encryption in transit and at rest
TLS · at rest
Row-level access control in the database
Row-level
Personal one-time links and e-mail codes
One-time
Access logging and backups; staff access only on request and logged
Logged

As stated in section 7 of the Privacy and Personal Data Policy.

Three layers of evidence

Data integrity, signature evidence and approval evidence.

Each layer leaves an artifact you can check: a report with a verdict, a certificate with a verification ID, a snapshot of who approved what.

  • Integrity report

    Data integrity

    Two canonical ownership engines, an append-only equity ledger and an integrity report with a verdict.

  • Certificate of completion

    Signature evidence

    Hashes, identity, time, device, consent text, stroke image, hash chain, an executed PDF with a verification ID and QR code, and a certificate of completion — verifiable on a public page.

  • Approval snapshot

    Approval evidence

    Append-only snapshots of who approved what and when; executing the corporate action is a separate confirmation with its own preview and hash.

Fields recorded for every signing and what each one proves
FieldPurpose
SHA-256 of the document and of its signing imageProves the exact file that was signed and detects any later change
Signer identity and confirmation methodShows who signed and how the identity was confirmed: e-mail code or passkey
UTC time of each actionFixes when the document was opened, confirmed and completed
IP address and device informationRecords where and from what device the action was taken
Consent text and versionKeeps the exact terms the signer accepted
Handwritten stroke imageStores the visible signature for the NX Strong level
Hash chain of evidenceEvery record includes the previous one, so the sequence cannot be rewritten
E-mail and view logShows when invitations were sent and when the document was viewed
VerificationPublic page
Illustrative example

Where your data lives

Six processors, each with one role.

  • Supabase, Inc.database, authentication and file storage on AWS infrastructure
  • Vercel, Inc.application hosting
  • OpenAI, L.L.C.document analysis and the assistant
  • Google LLCsign-in with a Google account, at the user's choice
  • Migadue-mail delivery
  • Paddle.com Market Ltdsubscription payments as reseller

Servers of these processors are located outside Uzbekistan (EU and USA); localisation of Uzbek citizens' personal data is in progress.

Read the Privacy policy

Access · Documents & AI · Payments & retention

Who sees what, and for how long.

  • Access

    • Workspace roles: OWNER, ADMIN, EDITOR, VIEWER.
    • The platform administrator is isolated from customer workspaces.
    • Invitations expire in 7 days by default.
  • Documents & AI

    • Documents are stored in a private bucket readable by workspace members.
    • Text sent for AI analysis is kept no longer than 30 days and is not used for training.
  • Payments & retention

    Payments are handled by third-party providers named in the Public Offer.

    Retention periods per the Privacy policy

    • Account data: until deletion plus 30 days.
    • Company data: while the workspace exists.
    • Signature evidence: at least five years.
    • Technical logs: up to 12 months.

    Only technically necessary cookies; no advertising or third-party analytics cookies.

Verify it yourself: start a workspace and run the integrity report.

30-day Founder trial on every new workspace.