Trust Center

How RILDocs protects your data, the standards we're built on, and where we are on the compliance path. Our defining control: your file is fingerprinted in your browser and never leaves your device.

Security at a glance

๐Ÿ”’ Privacy by design

Documents are hashed client-side (Web Crypto). We never receive, process, or store your file โ€” only its fingerprint and the metadata you enter.

๐Ÿงฎ Data minimization

We hold fingerprints, your metadata, cryptographic artifacts and anchors. There is no document content to breach.

๐Ÿ”‘ Key management

Signing & timestamp keys stay on the production host, owner-only permissions, out of source control and app backups. HSM custody on the qualified-tier roadmap.

๐ŸŒ Hardened hosting

Linux on Hetzner behind Cloudflare. TLS 1.2+ everywhere; origin reached only via an authenticated tunnel (no public inbound ports). Key-based SSH admin.

โ™พ๏ธ Durable proofs

Proofs survive any RILDocs outage โ€” blockchain anchors are permanent, and RFC 3161 tokens + PAdES certificates verify offline.

๐Ÿ”Ž Independently verifiable

Anyone can verify a proof with public blockchain explorers, standard OpenSSL, and Adobe Acrobat โ€” no trust in RILDocs required.

Standards & compliance

ItemStandardStatus
Document fingerprintSHA-256 (NIST FIPS 180-4)Live
Attestation signatureEd25519 (NIST FIPS 186-5)Live
Trusted timestampRFC 3161Live
Signed PDF certificatePAdES / ETSI EN 319 142Live
Evidence admissibilityU.S. Fed. R. Evid. 902(13) & 902(14)Live
Electronic recordsESIGN Act & UETALive
PrivacyGDPR data-minimization by designLive
Security controls auditSOC 2 Type IIIn preparation
ISMS certificationISO/IEC 27001In preparation
Qualified timestampseIDAS QTSP (EU legal presumption)Roadmap
We describe only what is true today. โ€œQualified,โ€ โ€œSOC 2,โ€ and โ€œISO 27001โ€ are shown as their real status โ€” claimed as achieved only once independently certified.

Sub-processors

ProviderPurposeData exposed
HetznerCompute / hostingStored metadata & fingerprints โ€” never documents
CloudflareEdge TLS, DNS, DDoS protectionRequest metadata in transit
Public blockchainsImmutable anchoringFingerprint (hash) only

Documents

๐Ÿ“„ Security Whitepaper Architecture, data handling, cryptography, hosting โ€” public โš–๏ธ Legal & Compliance Brief Why RILDocs holds up in court โ€” for legal & enterprise buyers
Our ISMS policy manual, SOC 2 / ISO 27001 gap analysis, and ETSI EN 319 421 TSA mapping are available to enterprise evaluators under NDA โ€” email [email protected].

Responsible disclosure

Found a security issue? We want to hear from you. Report it to [email protected]. We aim to acknowledge reports promptly and will work with you in good faith on remediation.