Enterprise-Grade Security Without Enterprise Complexity
Firma.dev protects your documents with bank-level encryption, strict access controls, and compliance-ready infrastructure. Built for teams that need security without the procurement headache.
Infrastructure (AWS)
Infrastructure (AWS)
Infrastructure
Firma.dev runs on AWS infrastructure in the European Union
AWS maintains SOC 2 Type II, ISO 27001, and HIPAA certifications. All customer data is stored in EU data centers.
Backups run every 60 seconds with point-in-time recovery. All backups are encrypted and stored in the EU. Full version history is available for every document.
System status is public at status.firma.dev. We do not offer formal SLAs at this time.
Encryption

Authentication & Access Control

API authentication
All API requests require key-based authentication. Rate limits protect against abuse. View rate limit details.
Dashboard login
Google and GitHub SSO are supported. Role-based access control lets account owners define what team members can see and do.


Customer Workspaces
Webhook Security
All webhook requests are signed using HMAC SHA-256
Every request includes:
X-Firma-Signaturewith your current signing secretX-Firma-Signature-Oldwith your previous secret during the 7-day rotation grace period
You can retrieve your signing secret from the dashboard and rotate it via the API. Always verify webhook signatures to prevent spoofing. View the Webhooks guide.

Audit Trails
Signer identity and email address
Timestamp of each action (viewed, signed, completed)
IP address of the signer
Document hash for tamper detection
Consent record confirming signer agreement
Completion status and certificate generation
Audit logs cannot be modified or deleted. You can retrieve them via the API for compliance reviews, legal disputes, or internal audits.
Compliance
E-signature validity
Firma.dev produces legally binding electronic signatures under:
ESIGN Act and UETA (United States)
Electronic signatures are legally equivalent to handwritten signatures for most transactions.
eIDAS SES and AdES (European Union)
Firma.dev supports Simple Electronic Signatures and Advanced Electronic Signatures with tamper-evident audit trails and signer identification.
UK eIDAS (United Kingdom)
Electronic signatures remain valid under retained EU law.
Data protection
Signer consent is captured and recorded before any signature is applied.
GDPR (European Union)
All data is stored in the EU. Firma.dev acts as a data processor on your behalf. A Data Processing Agreement is available for all customers. We assist with Data Subject requests as required.
HIPAA (United States)
Firma.dev runs on HIPAA-compliant AWS infrastructure, making it suitable for healthcare-related documents. If you require a Business Associate Agreement, contact support.

Security standards
Firma.dev is designed with SOC 2 principles in mind. SOC 2 Type II and ISO 27001 certifications are on our roadmap.
Long-Term Signature Validation (PAdES B-LTA)
Every signed document includes a PAdES B-LTA signature profile. This means signatures are tamper-proof and fully self-validating for 30+ years, with no dependency on external certificate authorities or online validation services after signing.
All required validation data (certificates, revocation information, and timestamps) is embedded directly in the PDF at signing time.


Personnel Access Control
Access to customer data is limited to specific Firma.dev personnel. Viewing document content requires explicit account-level permission.
Responsible Disclosure
We welcome vulnerability reports from security researchers. If you discover a potential security issue, please contact us at security@firma.dev. We review all reports and respond promptly.











