Built on cryptographic signing
AppliFlo defaults to PAdES — a stronger, tamper-evident signature standard than the simple click-to-sign most tools ship.
This Agreement is governed by the laws of the State of California, without regard to its conflict-of-laws rules.
This Agreement may be executed electronically and in counterparts, each of which is deemed an original.

- Root certificate authority
- Issuing CA
- AppliFlo signing keyCloud KMS
- nda-northwind.pdfPAdES
- PAdES sealing on Cloud KMS
- AES-256 at rest & TLS in transit
- Tenant-isolated workspaces
- API keys hashed, shown once
How signing works
PAdES embeds a cryptographic signature in the PDF, bound to its contents through a certificate chain. If the document is altered after signing, the seal breaks — and anyone can detect that independently, in a standard PDF reader.
Signing keys never leave Cloud KMS. Our application servers pass the PDF through for signing but never hold the private key.
Encryption
Documents are encrypted with AES-256 at rest and TLS in transit. Connector credentials and other secrets are encrypted at rest.
Tenant isolation
Every request — from the dashboard or an API key — is resolved to a single workspace before it touches a document. One workspace can never read another’s files, fields or envelopes.
Audit trail
Each envelope carries an audit trail: who acted, when, from which IP address and approximate geolocation.
Example rows.
API keys & rate limits
API keys are shown once, in full, at creation. From then on we store only a SHA-256 hash — a lost key can be revoked and reissued, never recovered.
- Per key
- 120 requests / min
- Shared pool
- 20 / min across detect, fill, send
AI data handling
AppliFlo uses AI to detect fields and summarize documents. Our intent is that customer and CRM data is used to operate the service, not to train foundation models.
Compliance
AppliFlo is designed to support ESIGN/UETA electronic-signature workflows. We do not claim certifications we do not hold; as formal programs progress, we will state their status plainly here.
Sub-processors & status
Our sub-processor list and status page will be linked here as they are published. For a security review, contact us.