How we protect your workspace.
Your documents are private to your workspace. Share and signing links are unguessable, expire, and can be revoked. Here is what’s in place today, and what isn’t.
Updated
What’s in place
Every private page and action checks that you’re signed in and a member of the workspace. Share and signing links use long random tokens that expire and can be revoked. Documents out for signature, and signed documents, are locked.
- Connector tokens are stored as hashes and checked on every request.
- Sign-in, signing, share links and connectors are rate-limited.
- We monitor errors in production.
What we don’t claim
Triplewave doesn’t hold SOC 2 or ISO 27001 and hasn’t published a penetration test. We don’t offer SSO, customer-managed encryption keys or a contractual uptime SLA yet.
- Keep your own copies of documents that matter.
- Give connectors the narrowest permissions that work, and revoke the ones you don’t use.
- Write to hello@droidsize.com if you think an account or link has been compromised.
Worth knowing
- No service can guarantee perfect security, and no independent auditor has reviewed this page.