Trust and security

What happens to your documents, in plain words.

Signing is about trust, so here is everything we can tell you about where your data lives, who touches it and how to check our work yourself.

Your data stays in the EU

TrustInk runs on Amazon Web Services in Ireland (eu-west-1). Documents, signed PDFs, evidence summaries, case data and the keys that sign them are stored and processed there, and our emails leave from the same region.

Our web pages and scripts are delivered through a content delivery network for speed. It carries only the public pages, never your documents: those travel straight between the browser and eu-west-1 over TLS.

Region
AWS eu-west-1, Ireland
Encryption
At rest and in transit (TLS)
Signing keys
AWS KMS, never exported
Tracking
None on trustink.io

Sub-processors

The companies that help us run TrustInk, and what they see. We tell customers at least 30 days before we add or replace one.

ProviderWhat forWhereWhat they see
Amazon Web Services EMEA SARLHosting, storage, databases, key management, sign-in (Cognito), email delivery (Amazon SES)EU (Ireland, eu-west-1)All service data, encrypted
Stripe Payments Europe, Ltd.Payments for paid plans (planned)EU (Ireland)Billing details of customers; no documents
Sectigo (Europe) S.L.Qualified timestamps (RFC 3161)EU (Spain)A document fingerprint only; no document, no personal data
DigiCert, Inc.Timestamps when the first authority does not answerGlobalA document fingerprint only; no document, no personal data

Timestamp authorities never receive a document or personal data. We list them so you know every party a signed document depends on.

Retention and deletion

  1. A limit per plan

    Each plan sets the longest time documents may be kept. The default and the limits are published with the plans.

  2. Your setting

    Within that limit you choose how long your tenant keeps cases. Shorter is always possible.

  3. Deleted, not archived

    When the time is up, TrustInk deletes the original and signed PDFs, the evidence summary and the participants’ personal data.

  4. What you keep

    Signed documents you downloaded or received by webhook stay with you and remain verifiable on their own.

The TrustInk root certificate

Every signed PDF chains up to the TrustInk Root CA. Adobe Reader does not know this root out of the box, so it shows the signatures as "validity unknown" until you trust it once. After that, every TrustInk document shows its signatures as valid.

Download trustink-root.crt

DER certificate, published with the revocation lists at http://crl-dev.trustink.io/

Trust it in Adobe Acrobat Reader

  1. Download the root certificate with the button above.
  2. Open Adobe Acrobat Reader and go to Preferences (Windows: Edit › Preferences; macOS: Acrobat Reader › Settings), then Signatures.
  3. Under Identities & Trusted Certificates choose More…, select Trusted Certificates and click Import.
  4. Browse to trustink-root.crt, add it to the list and click Import.
  5. Select “TrustInk Root CA” in the list, choose Edit Trust, tick “Use this certificate as a trusted root” and confirm with OK.
  6. Open the signed PDF again: the signature panel now shows every signature as valid.

Report a vulnerability

If you believe you have found a security problem in TrustInk, we want to hear about it, and we will work with you to fix it.

Write tosecurity@trustink.io

Machine-readable: /.well-known/security.txt

Our disclosure policy

  • Report privately to security@trustink.io with enough detail to reproduce the problem. Encrypt it if you like; ask us for a key.
  • Give us reasonable time to fix it before you tell anyone else; we aim for 90 days at most.
  • Only test against your own account and data. Do not access, change or delete other people’s data, do not degrade the service and do not use social engineering or physical attacks.
  • We confirm receipt within three working days, keep you informed and credit you when the fix is out, if you want.
  • We will not take legal action against research done in good faith within these rules.