Trust Center

Security you can defend to legal.

InkSwift is built for regulated industries — healthcare, finance, government contracting, and enterprise procurement.

SOC 2 Type II

In progress

Audit underway with an AICPA-accredited firm. Letter of engagement available on request.

HIPAA-ready

BAA available

Encryption, access controls, and audit logging that meet HIPAA Security Rule. BAA on Enterprise.

GDPR & CCPA

Compliant

Lawful basis, DSAR workflow, regional data residency on request, sub-processor transparency.

eIDAS / ESIGN / UETA

Compliant

Signatures meet US ESIGN, UETA, and EU eIDAS simple electronic signature standards.

Security controls

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Signature images and audit data are encrypted column-level.

Least-privilege access

Row-level security on every tenant table. No engineer has standing access to customer documents.

Tamper-evident audit log

Every view, sign, and send event is hashed and timestamped. Exportable as a court-ready PDF certificate.

Continuous monitoring

Automated dependency scanning, secret rotation, and 24/7 anomaly detection on auth events.

Sub-processors

We notify customers in writing 30 days before adding any new sub-processor.

ProviderPurposeRegion
Supabase / AWS (us-east-1)Primary database, auth, file storageUnited States
CloudflareEdge runtime, DDoS protection, WAFGlobal
PaddlePayments and tax (PCI-DSS Level 1)EU / US
ResendTransactional email deliveryUnited States

Data Processing Agreement

Pre-signed GDPR-compliant DPA available for Business and Enterprise plans. Standard contractual clauses included.

Request DPA

Security whitepaper

Architecture diagrams, encryption details, incident response runbooks, and penetration test summaries.

Request whitepaper

Report a vulnerability

We respond to security reports within 24 hours. PGP key available on request.

security@inkswift.com
See enterprise pricing