Trust Center
Everything your legal and security teams
need to review.
Subprocessors, compliance posture, SLA, incident policy, and shortcuts to the legal documents. This page is updated when there are material changes; if you need information you can't find here, email [email protected].
Subprocessors
The 7 companies that touch your data, grouped by function.
Canonical list also used in clause 8 of the DPA. Business customers receive 30 days' advance notice when a new subprocessor is added.
Storage
Cloudflare R2 (Cloudflare Inc.)
EE.UU. / globalAlmacenamiento de documentos PDF y reportes de evidencia
Infrastructure
Proveedor de PostgreSQL gestionado
EE.UU. / UEBase de datos relacional con cifrado en reposo y row-level security
Payments
Stripe Inc.
EE.UU.Procesamiento de pagos y suscripciones
Identity
Truora
Colombia / LATAMVerificación de identidad (cédula, OCR, biometría con prueba de vida)
Resend
EE.UU.Envío de correos transaccionales
Artificial intelligence
Anthropic, PBC
EE.UU.Modelos de IA para análisis de cláusulas, extracción de campos y chat
Timestamping
Autoridad de timestamping (TSA)
UESellado de tiempo RFC 3161 para firmas y reportes de evidencia
Compliance posture
What we have today, what's on the roadmap, and what doesn't apply.
We'd rather be explicit. If your internal compliance requires anything in the “Roadmap” column as a blocking condition, let's talk before you adopt the platform.
- ESIGN Act (15 U.S.C. §7001) & UETA complianceLive
Operates as a simple electronic signature under the federal ESIGN Act and state Uniform Electronic Transactions Act framework. Documented at /us/legal/electronic-signature-legality.
- Reproducible public verificationLive
Server-recomputed hashes, an offline export for expert witnesses, and a published root CA.
- AES-256 encryption at rest · TLS 1.2+ in transitLive
Applied to documents, evidence reports, and backups.
- Multi-tenant Row-Level SecurityLive
Data isolation enforced by RLS policies in Postgres.
- DPA available for business customersLive
See /us/legal/dpa — available to Teams, Enterprise, and other business customers.
- Responsible disclosure (security.txt)Live
Policy published at /.well-known/security.txt — response within 72 business hours.
- Status page with incident historyLive
/status shows components and maintenance windows in real time.
- Security headers & CSPLive
A rating on securityheaders.com: Content-Security-Policy, HSTS with preload, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. TLS 1.3.
- ISMS aligned with ISO/IEC 27001:2022Live
A documented information security management system: an approved policy, a Statement of Applicability covering the 93 Annex A controls, and a risk register. It is not a certification; certification by an accredited body is planned as demand warrants.
- CSA STAR Level 1 (CAIQ v4.1)Live
CAIQ v4.1 self-assessment published in the Cloud Security Alliance's public registry (STAR Level 1). It is a self-assessment, not an audited certification, and anyone can look it up. View the listing on CSA.
- ISO 27001 (audited certification)Roadmap
The ISMS is already aligned (see above). Certification by an accredited body will begin as demand from enterprise customers warrants it.
- SOC 2 Type IIRoadmap
Process to begin as the enterprise customer base scales. No committed date.
- PCI DSSN/A
Card processing is 100% outsourced to Stripe (PCI DSS Level 1). Kligrafia does not store, process, or transmit card data, so its scope is limited to SAQ A.
- HIPAAN/A
Out of scope: Kligrafia does not process protected health information (PHI) covered by HIPAA. If your organization needs a Business Associate Agreement, talk to us before you adopt the platform.
- State-level qualified/certified signature accreditationN/A
Doesn't apply to our current simple electronic-signature model under the ESIGN Act and UETA. We'll evaluate it if demand emerges.
Cryptographic verification
Anyone can verify a document without trusting us.
We publish everything a judge, an expert witness, or your counterparty needs to independently validate the integrity of an envelope. The hashes are recomputed server-side, and the export includes a script that revalidates the chain without access to Kligrafia.
Kligrafia's own certificate authority (Didi Solutions C.A., RSA-4096) — the same signing infrastructure used across every Kligrafia market. It seals every document with a PAdES signature. Import the certificate into your reader to validate the seal.
SHA-256 fingerprint
CA:30:72:17:74:22:9A:69:E3:90:9D:A6:47:D7:C6:93:1E:DE:57:AC:C2:43:85:B1:61:FE:98:9C:6D:6C:39:D3
Download certificate (PEM)Every event is chained with SHA-256 over its canonical content and the previous event's hash. The public export includes everything needed to recompute every hash without access to our database.
Trusted timestamp
DigiCert as the primary TSA, with Sectigo and FreeTSA as backup. The timestamp elevates the signature to PAdES B-T level, and supports the authentication standard of Federal Rule of Evidence 901.
SLA & commitments
What we promise, in numbers.
Commitments in effect as of July 2026. Formal per-plan terms are detailed at /us/legal/terms.
View service status- Target uptime, Enterprise plan99.9% monthly
- Target first-response time for support24 business hours (Teams plan) · 8 business hours (Enterprise)
- Target first-response time for security reports72 business hours
- Notice of subprocessor changes to business customers30 days in advance
- Encrypted backup retention90 days with periodic restore testing
Incident response
Five steps, no improvising.
When something breaks, what matters isn't promising perfection — it's having a process. Here's ours.
Step 1
Detection & triage
Automated monitoring plus external reports. Initial severity (P0/P1/P2/P3) and scope classification within the first hour.
Step 2
Containment
Immediate mitigation to stop loss or exposure. For security incidents: isolation, credential rotation, blocking attack vectors.
Step 3
Communication
For P0/P1 incidents: an update on /status within 30 minutes of confirmation, direct communication to affected customers, and, if applicable, notice under clause 11 of the DPA.
Step 4
Eradication & recovery
Removing the root cause, restoring services, verifying data integrity. Target time depends on severity.
Step 5
Public post-mortem (when applicable)
For incidents with material customer impact, we publish a post-incident analysis with root cause and the corrective actions taken.
Shortcuts
Key legal and operational documents.
Frequently asked questions
What legal and procurement teams ask.
- Where is my data physically located?
- PDFs and evidence reports live in Cloudflare R2 (a global network, primarily US/EU). The relational database runs on a managed provider with encryption at rest (US/EU). Specific regional details are in the subprocessor list above. If you have strict data-residency requirements, let's talk before you adopt the platform.
- Who is the controller and who is the processor?
- You (the business customer) act as the Controller of the personal data you upload, manage, or process through the platform. Kligrafia (Those Who Build Dreams, Inc.) acts as the Processor, handling data according to your documented instructions in the DPA and Terms.
- Can I request a custom security questionnaire?
- Yes — for Teams, Enterprise, and other business customers, we complete vendor questionnaires (SIG, CAIQ-Lite, or internal templates) under mutual NDA. Email [email protected] with the context.
- How do I find out if Kligrafia adds a new subprocessor?
- We notify business customers at least 30 days in advance (DPA clause 8). If you have reasonable objections, you may object; if we can't reach a resolution, you may terminate your subscription without penalty for the unconsumed portion.
- What happens to my data if I cancel my subscription?
- We keep data in an exportable format for a reasonable period defined in the Terms, during which you can download every envelope and evidence report. After that period, data is deleted or anonymized as set out in the DPA, except where mandatory legal retention applies (billing, tax records).
Need a questionnaire or an NDA first?
For Teams, Enterprise, and other business customers, we complete vendor questionnaires under mutual NDA. Write to us with the context.