Skip to main content
Wisenotary

Security

What happens to your client's document

Written for the person who has to sign off on using us. Every answer below describes a control that runs today; where we do not have something, this page says so.

Who sees my client's documents?
Our own staff under role-based access, and the sub-processors listed below. Each notary or translator engaged for an assignment is also a sub-processor, bound by a written agreement carrying the Article 28(3) obligations.
What stops a malicious file being uploaded?
Uploads are typed from their bytes rather than their file extension, and the detected type must match the claimed one. Each upload path has its own allowlist of document formats - PDF, JPEG, PNG, WebP, HEIC and HEIF are accepted everywhere, and a couple of paths also take TIFF and Word (.doc, .docx) - all capped at 25 MB. An executable renamed to invoice.pdf is refused before it reaches storage. We do not run a scanner looking for known malware. Where only the six image and PDF formats are taken, that surface is narrow, because none of them execute. Where Word is also accepted, it is a residual risk we name rather than one we have engineered away.
Who confirms the signer is who they say they are?
Identity documents are parsed from their machine-readable zone and matched against the details already on file. The verification capture is attached to the notarial act, and the register records that the act was performed remotely and by which communication technology. The platform does not host or record the session itself; the notary uses their own commissioned tooling.
How do I know a document was not altered afterwards?
The stored signed PDF is SHA-256 hashed, and that hash is recorded against the signing event. Recomputing the hash later and comparing it to the recorded value reveals any change to the file, however small. Where the signer's authentication level is QES and the destination requires it, a qualified PAdES seal is applied to the document as well.
What is logged, and who can read it?
Sign-ins, case status changes, PII reveals, administrative actions, and shipping and invoice events are written to an audit log secured by a hash chain: each entry's hash covers the one before it, so a retro-edit or deletion is detectable by re-walking the chain. Reading it requires a management or admin role.
Where does the data physically sit?
Documents are in AWS S3 in us-east-2. The database is Aurora PostgreSQL in the same region, with 14 days of point-in-time recovery and deletion protection on. Weekly and monthly backups copy to a vault in a second region; daily backups stay in the primary one.
What do we sign with you?
A Data Processing Agreement carrying the Article 28(3) terms, including audit and inspection rights and the sub-processor list below. You are the controller; we are the processor.

Sub-processors

Every company that processes personal data on our behalf. We name our infrastructure because you can verify it from your own browser in a minute, and a list that omits what you can see is worth nothing.

  • Amazon Web Services, Inc.
    Purpose
    Hosting, database, document storage, transactional email, and AI inference
    Location
    USA (us-east-2)
  • Stripe, Inc.
    Purpose
    Card payment processing
    Location
    USA
  • PayPal Holdings, Inc.
    Purpose
    Payment processing
    Location
    USA
  • Telnyx LLC
    Purpose
    SMS and voice verification
    Location
    USA
  • Shippo, Inc.
    Purpose
    Courier labels and shipment tracking
    Location
    USA
  • HighLevel Inc. (GoHighLevel)
    Purpose
    Customer relationship management and communications
    Location
    USA
  • Google LLC
    Purpose
    Website analytics
    Location
    USA

In addition, the notaries and translators engaged for an individual assignment act as sub-processors for that assignment, each under a written agreement carrying the Article 28(3) obligations. We disclose this category and its contractual terms rather than the identity of individual professionals, which is commercially sensitive. You may request the identity of the professionals engaged on your own matters at any time.

The agreement itself

The full Data Processing Agreement, including the sub-processor table above, audit rights and the breach-notification window.