Security

No theater: what exists, explained plainly.

Brokers audit. This page answers — with names, not promises.

Audit trail per document

Who opened and who downloaded each file, with name and time.

Sealed, auditable signatures

Every signed document carries a cryptographic seal with a timestamp and a hash-chained log that makes any alteration evident.

Encrypted credentials

Each agency's integration keys are stored encrypted (AES-GCM); nobody sees them in the clear, not even us.

Full activity log

Auditable activity record per agent and per agency, with no gaps and a defined retention window.

Login events with geolocation

Every sign-in is logged with its location and device.

Multi-tenant isolation

Each agency's data lives isolated. No one sees what isn't theirs.

Granular roles and permissions

You define exactly what each role sees and can do.

GDPR deletion requests

Data-subject deletion and export, resolved from the panel.

Per-agency webhooks and API keys

Integrate with your systems using your own keys, revocable anytime.

Defense in depth

Minimal surface and layered control — not a single door.

The honest close

No serious system promises "unbreakable." What we do guarantee: minimal surface, defense in depth, and your data always exportable.