Trust Center

Trust built into every contract

Secure electronic signatures, complete audit trails, documented provider locations, and transparent security practices for modern contract work.

Trust at a glance

The essentials, clearly documented

A quick overview of how Scriboflow handles contract security, signing evidence, and privacy.

Documented infrastructure
The primary production database region is Frankfurt. Other infrastructure providers may process in the United States and globally under documented safeguards.
Secure Signatures
Electronic signatures support clear signer actions and identity options such as MitID and BankID through Idura.
Complete Audit Trails
Important contract actions are recorded from creation through signing and completion.
Privacy & Transparency
Policies, infrastructure details, and privacy-focused practices are kept clear and easy to review.

Infrastructure

Transparent infrastructure foundations

Core data regions and global provider operations are documented without claiming Europe-only processing.

Data Residency
The production Supabase project uses Frankfurt, Germany as its primary database region. Vercel documents United States and global processing, and Google Cloud may process where it or its subprocessors operate. The provider register identifies current locations and safeguards.

Infrastructure Providers

Supabase, Inc.
Managed database, authentication, realtime services, and object storage. Primary production region: Frankfurt, Germany. Limited provider support and ancillary processing may occur from other locations under the provider terms.
Google Cloud EMEA Limited and Google group processors
Cloud object storage and supporting infrastructure for files and generated contract artefacts. Location depends on the configured resource and provider operations. Google may process where it or its subprocessors maintain facilities, as described in its DPA.
Vercel Inc.
Application hosting, content delivery, server-side request processing, deployment, and operational logs. United States and other global locations used by Vercel and its subprocessors.

Security

Core practices for protecting contract work

Scriboflow combines account controls, data protection, and activity visibility to help keep contract work protected.

Account Security
Controls for keeping organisation access protected.
  • Multi-factor authentication
  • Email verification
  • Role-based organisation access
Data Protection
Safeguards for documents, metadata, and contract records.
  • Encryption in transit and provider-supported encryption at rest
  • Organisation and row-level access controls
  • Documented infrastructure providers
Monitoring & Logging
Visibility into important product and contract events.
  • Activity logs
  • Contract audit timelines
  • IP tracking
View security overview

Signatures & audit trails

Evidence for every important signing moment

Scriboflow is designed to keep signature choices and contract history visible from one place.

Timeline preview
Contract timeline
  1. Contract created

    Timestamp and actor details

  2. Signature request sent

    Timestamp and actor details

  3. First signer opened request

    Timestamp and actor details

  4. First signer signed

    Timestamp and actor details

  5. Second signer opened request

    Timestamp and actor details

  6. Second signer signed

    Timestamp and actor details

  7. All signatures completed

    Timestamp and actor details

Evidence trail
Clear contract history
  • Timestamps
  • Signer activity
  • IP tracking
  • Signature events
  • Full contract history
Signature options
Flexible signing flows
  • Email-link signatures
  • Drawn signatures
  • Checkbox consent
  • MitID / BankID / identity-based signatures through Idura

Contract protection

How Scriboflow Protects Your Contracts

A simple view of the contract journey from secure creation to preserved evidence.

Create
Contract work starts in a secure organisation with verified user access.
Store
Contract data is protected with encryption in transit, provider-supported encryption at rest, and organisation-scoped access controls.
Sign
Signees access contracts through secure signing links, with optional identity verification through supported providers.
Preserve
Important events are recorded in the audit timeline, including views, signing actions, timestamps, and IP tracking.

Transparency

Transparency by default

Scriboflow clearly explains how customer data is stored, processed, and protected before businesses upload contracts.

Clear Infrastructure
Primary regions, global provider operations, and transfer safeguards are documented in one place.
Visible Security Practices
Verified practices such as MFA, encryption, access controls, and activity logs are easy to review.
Honest Compliance Roadmap
Scriboflow is actively working toward SOC 2 compliance without claiming certification before it is complete.
Public Documentation
Security, privacy, legal, DPA, and subprocessor information is organized for customer review.

Privacy & compliance

Built with clear privacy expectations

Scriboflow is built with European privacy expectations in mind and keeps its compliance roadmap clear.

GDPR
Scriboflow is built with European privacy requirements in mind.
DPA
The public Data Processing Agreement is incorporated automatically into the Terms.
SOC 2
Scriboflow is actively working toward SOC 2 compliance.