Trust Center

Everything your legal and security teamsneed to review.

Subprocessors, compliance posture, SLA, incident policy, and shortcuts to the legal documents. This page is updated when there are material changes; if you need information you can't find here, email [email protected].

Subprocessors

The 7 companies that touch your data, grouped by function.

Canonical list also used in clause 8 of the DPA. Business customers receive 30 days' advance notice when a new subprocessor is added.

Storage

  • Cloudflare R2 (Cloudflare Inc.)

    EE.UU. / global

    Almacenamiento de documentos PDF y reportes de evidencia

Infrastructure

  • Proveedor de PostgreSQL gestionado

    EE.UU. / UE

    Base de datos relacional con cifrado en reposo y row-level security

Payments

  • Stripe Inc.

    EE.UU.

    Procesamiento de pagos y suscripciones

Identity

  • Truora

    Colombia / LATAM

    Verificación de identidad (cédula, OCR, biometría con prueba de vida)

Email

  • Resend

    EE.UU.

    Envío de correos transaccionales

Artificial intelligence

  • Anthropic, PBC

    EE.UU.

    Modelos de IA para análisis de cláusulas, extracción de campos y chat

Timestamping

  • Autoridad de timestamping (TSA)

    UE

    Sellado de tiempo RFC 3161 para firmas y reportes de evidencia

Compliance posture

What we have today, what's on the roadmap, and what doesn't apply.

We'd rather be explicit. If your internal compliance requires anything in the “Roadmap” column as a blocking condition, let's talk before you adopt the platform.

  • ESIGN Act (15 U.S.C. §7001) & UETA compliance
    Live

    Operates as a simple electronic signature under the federal ESIGN Act and state Uniform Electronic Transactions Act framework. Documented at /us/legal/electronic-signature-legality.

  • Reproducible public verification
    Live

    Server-recomputed hashes, an offline export for expert witnesses, and a published root CA.

  • AES-256 encryption at rest · TLS 1.2+ in transit
    Live

    Applied to documents, evidence reports, and backups.

  • Multi-tenant Row-Level Security
    Live

    Data isolation enforced by RLS policies in Postgres.

  • DPA available for business customers
    Live

    See /us/legal/dpa — available to Teams, Enterprise, and other business customers.

  • Responsible disclosure (security.txt)
    Live

    Policy published at /.well-known/security.txt — response within 72 business hours.

  • Status page with incident history
    Live

    /status shows components and maintenance windows in real time.

  • Security headers & CSP
    Live

    A rating on securityheaders.com: Content-Security-Policy, HSTS with preload, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. TLS 1.3.

  • ISMS aligned with ISO/IEC 27001:2022
    Live

    A documented information security management system: an approved policy, a Statement of Applicability covering the 93 Annex A controls, and a risk register. It is not a certification; certification by an accredited body is planned as demand warrants.

  • CSA STAR Level 1 (CAIQ v4.1)
    Live

    CAIQ v4.1 self-assessment published in the Cloud Security Alliance's public registry (STAR Level 1). It is a self-assessment, not an audited certification, and anyone can look it up. View the listing on CSA.

  • ISO 27001 (audited certification)
    Roadmap

    The ISMS is already aligned (see above). Certification by an accredited body will begin as demand from enterprise customers warrants it.

  • SOC 2 Type II
    Roadmap

    Process to begin as the enterprise customer base scales. No committed date.

  • PCI DSS
    N/A

    Card processing is 100% outsourced to Stripe (PCI DSS Level 1). Kligrafia does not store, process, or transmit card data, so its scope is limited to SAQ A.

  • HIPAA
    N/A

    Out of scope: Kligrafia does not process protected health information (PHI) covered by HIPAA. If your organization needs a Business Associate Agreement, talk to us before you adopt the platform.

  • State-level qualified/certified signature accreditation
    N/A

    Doesn't apply to our current simple electronic-signature model under the ESIGN Act and UETA. We'll evaluate it if demand emerges.

Cryptographic verification

Anyone can verify a document without trusting us.

We publish everything a judge, an expert witness, or your counterparty needs to independently validate the integrity of an envelope. The hashes are recomputed server-side, and the export includes a script that revalidates the chain without access to Kligrafia.

Kligrafia Root CA

Kligrafia's own certificate authority (Didi Solutions C.A., RSA-4096) — the same signing infrastructure used across every Kligrafia market. It seals every document with a PAdES signature. Import the certificate into your reader to validate the seal.

SHA-256 fingerprint

CA:30:72:17:74:22:9A:69:E3:90:9D:A6:47:D7:C6:93:1E:DE:57:AC:C2:43:85:B1:61:FE:98:9C:6D:6C:39:D3

Download certificate (PEM)
Audit chain

Every event is chained with SHA-256 over its canonical content and the previous event's hash. The public export includes everything needed to recompute every hash without access to our database.

Trusted timestamp

DigiCert as the primary TSA, with Sectigo and FreeTSA as backup. The timestamp elevates the signature to PAdES B-T level, and supports the authentication standard of Federal Rule of Evidence 901.

SLA & commitments

What we promise, in numbers.

Commitments in effect as of July 2026. Formal per-plan terms are detailed at /us/legal/terms.

View service status
  • Target uptime, Enterprise plan99.9% monthly
  • Target first-response time for support24 business hours (Teams plan) · 8 business hours (Enterprise)
  • Target first-response time for security reports72 business hours
  • Notice of subprocessor changes to business customers30 days in advance
  • Encrypted backup retention90 days with periodic restore testing

Incident response

Five steps, no improvising.

When something breaks, what matters isn't promising perfection — it's having a process. Here's ours.

  1. Step 1

    Detection & triage

    Automated monitoring plus external reports. Initial severity (P0/P1/P2/P3) and scope classification within the first hour.

  2. Step 2

    Containment

    Immediate mitigation to stop loss or exposure. For security incidents: isolation, credential rotation, blocking attack vectors.

  3. Step 3

    Communication

    For P0/P1 incidents: an update on /status within 30 minutes of confirmation, direct communication to affected customers, and, if applicable, notice under clause 11 of the DPA.

  4. Step 4

    Eradication & recovery

    Removing the root cause, restoring services, verifying data integrity. Target time depends on severity.

  5. Step 5

    Public post-mortem (when applicable)

    For incidents with material customer impact, we publish a post-incident analysis with root cause and the corrective actions taken.

Frequently asked questions

What legal and procurement teams ask.

Where is my data physically located?
PDFs and evidence reports live in Cloudflare R2 (a global network, primarily US/EU). The relational database runs on a managed provider with encryption at rest (US/EU). Specific regional details are in the subprocessor list above. If you have strict data-residency requirements, let's talk before you adopt the platform.
Who is the controller and who is the processor?
You (the business customer) act as the Controller of the personal data you upload, manage, or process through the platform. Kligrafia (Those Who Build Dreams, Inc.) acts as the Processor, handling data according to your documented instructions in the DPA and Terms.
Can I request a custom security questionnaire?
Yes — for Teams, Enterprise, and other business customers, we complete vendor questionnaires (SIG, CAIQ-Lite, or internal templates) under mutual NDA. Email [email protected] with the context.
How do I find out if Kligrafia adds a new subprocessor?
We notify business customers at least 30 days in advance (DPA clause 8). If you have reasonable objections, you may object; if we can't reach a resolution, you may terminate your subscription without penalty for the unconsumed portion.
What happens to my data if I cancel my subscription?
We keep data in an exportable format for a reasonable period defined in the Terms, during which you can download every envelope and evidence report. After that period, data is deleted or anonymized as set out in the DPA, except where mandatory legal retention applies (billing, tax records).

Need a questionnaire or an NDA first?

For Teams, Enterprise, and other business customers, we complete vendor questionnaires under mutual NDA. Write to us with the context.