Security
Ink codes
- Codes are produced by a cryptographically secure random number generator, from an alphabet chosen to avoid look-alike characters, and are single-use: once written on a document and registered, a code cannot be reused.
- Each code is tied to the account that generated it, the time it was generated, and the document it was registered with. Every verification attempt is logged.
Accounts
- Passwords are stored only as salted PBKDF2-SHA256 hashes with 600,000 iterations; we cannot read them.
- Sign-in attempts are rate-limited per account and per network address, and repeated failures lock the account temporarily.
- Password reset and email confirmation links are single-use, expire quickly, and are stored only as hashes.
- You can end every session from Settings, and deleting your account erases its data immediately.
Documents and data
- All traffic uses HTTPS with TLS 1.2 or newer, with HSTS enabled.
- Documents are held in private object storage and the database is encrypted at rest; verifiers never see document images or your contact details.
- Uploads are checked by content, not just by file name, and are size-limited.
- Backups are taken daily and retained for 14 days; deleted files are recoverable by us for 30 days to protect against accidental loss, then purged.
Operations
- Sigvera runs on Microsoft Azure in the United States; the database accepts connections only from our own application servers.
- Administrative access requires multi-factor authentication, and every administrative action is written to an audit log.
- Payments are processed by Stripe, which holds your payment details; we store only a customer reference.
- Error rates and availability are monitored, and alerts go to our on-call address.
Reporting a vulnerability
Email support@sigvera.com with "Security" in the subject. We acknowledge reports within two business days, keep you informed, and ask that you give us a reasonable time to fix the issue before disclosing it. We do not pursue researchers who act in good faith.