Security

What we do, stated plainly. We only list measures that are in place.

Ink codes

  • Codes are produced by a cryptographically secure random number generator, from an alphabet chosen to avoid look-alike characters, and are single-use: once written on a document and registered, a code cannot be reused.
  • Each code is tied to the account that generated it, the time it was generated, and the document it was registered with. Every verification attempt is logged.

Accounts

  • Passwords are stored only as salted PBKDF2-SHA256 hashes with 600,000 iterations; we cannot read them.
  • Sign-in attempts are rate-limited per account and per network address, and repeated failures lock the account temporarily.
  • Password reset and email confirmation links are single-use, expire quickly, and are stored only as hashes.
  • You can end every session from Settings, and deleting your account erases its data immediately.

Documents and data

  • All traffic uses HTTPS with TLS 1.2 or newer, with HSTS enabled.
  • Documents are held in private object storage and the database is encrypted at rest; verifiers never see document images or your contact details.
  • Uploads are checked by content, not just by file name, and are size-limited.
  • Backups are taken daily and retained for 14 days; deleted files are recoverable by us for 30 days to protect against accidental loss, then purged.

Operations

  • Sigvera runs on Microsoft Azure in the United States; the database accepts connections only from our own application servers.
  • Administrative access requires multi-factor authentication, and every administrative action is written to an audit log.
  • Payments are processed by Stripe, which holds your payment details; we store only a customer reference.
  • Error rates and availability are monitored, and alerts go to our on-call address.

Reporting a vulnerability

Email support@sigvera.com with "Security" in the subject. We acknowledge reports within two business days, keep you informed, and ask that you give us a reasonable time to fix the issue before disclosing it. We do not pursue researchers who act in good faith.