Security & compliance

Documents worth trusting in court.

Signatures are only useful if they hold up. Ecylaa treats the integrity of your documents and the evidence behind them as the core of the product.

Encryption everywhere

TLS 1.3 in transit and AES-256 at rest. Documents are encrypted per-tenant and access is scoped by signed, short-lived tokens.

Tamper-evident audit trail

Every view, field change, and signature is hashed into a sealed certificate of completion — independently verifiable after the fact.

Legally sound signatures

Signatures are built to meet the EU eIDAS regulation and the US ESIGN Act. Qualified signatures with ID verification are available as an add-on.

SSO & granular roles

SAML SSO, SCIM provisioning, and per-workspace roles so the right people send, sign, and read documents.

Data residency

Choose where documents are stored and processed — EU, UK, or US — to match your compliance obligations.

Retention controls

Set how long signed documents and evidence are kept, with export and deletion you control.

Frameworks

Built to the standards your customers ask about.

Need our security documentation or have a questionnaire to complete? Request access and we'll work through it with you under NDA.

  • UK GDPR & EU GDPR compliant
  • CCPA compliant
  • eIDAS & ESIGN signatures
  • SOC 2-aligned controls
  • ISO 27001-aligned practices
  • Independent penetration testing