Enterprise-Grade Protection
Security is not a feature; it's our foundation. We use world-class encryption and regional hosting to protect your most sensitive legal agreements.
Legal Compliance
Contractso facilitates legally binding signatures that stand up in court:
- eIDAS Compliant (EU): Meeting the standards for electronic identification and trust services across Europe.
- ESIGN & UETA (US): Full compliance with United States federal and state laws.
- Digital Audit Trail: Every contract includes a cryptographically sealed log with IP addresses, timestamps, and event history.
1. Regional Data Residency
We believe in keeping data where it belongs. Contractso utilizes a high-availability infrastructure:
- EU Hosting: Our primary databases and document storage are located on Hostinger Enterprise servers in Germany.
- Redundancy: We utilize Google Cloud for distributed backups and disaster recovery to ensure 99.9% uptime.
2. Communication Security
How we handle the delivery of your sensitive documents:
- Email Infrastructure: All contract notifications are sent via our own dedicated email infrastructure, ensuring no third-party has access to the email content during the relay.
- SMS Authentication: Secure two-factor notifications and signer identity verification are powered by Twilio using encrypted API channels.
3. Encryption Standards
We protect data at every stage of its lifecycle:
- At Rest: All stored documents and personal data are encrypted using AES-256 (Advanced Encryption Standard).
- In Transit: Data moving between your browser and our servers is protected by TLS 1.3 encryption over HTTPS.
4. Payment Security
Payment processing is handled entirely by Stripe. Contractso never sees or stores your full credit card number. Stripe is a PCI-DSS Level 1 Service Provider, the most stringent level of certification in the payments industry.
5. Continuous Monitoring
Our security team performs regular checks to keep the platform safe:
- Automated vulnerability scanning of our German-based server nodes.
- Real-time threat detection and DDoS protection.
- Strict internal access controls (Principle of Least Privilege).
6. Security Inquiries
Found a potential security issue? We take all reports seriously. Please contact us at [email protected]. We aim to acknowledge all reports within 12 hours.