Skip to content

Built on cryptographic signing

AppliFlo defaults to PAdES — a stronger, tamper-evident signature standard than the simple click-to-sign most tools ship.

Signature is validDocument unchanged since it was sealed · Example
  1. Root certificate authority
  2. Issuing CA
  3. AppliFlo signing keyCloud KMS
  4. nda-northwind.pdfPAdES
SHA-256 4f1c9e27b0d3…6be2a90e
  • PAdES sealing on Cloud KMS
  • AES-256 at rest & TLS in transit
  • Tenant-isolated workspaces
  • API keys hashed, shown once

How signing works

PAdES embeds a cryptographic signature in the PDF, bound to its contents through a certificate chain. If the document is altered after signing, the seal breaks — and anyone can detect that independently, in a standard PDF reader.

Signing keys never leave Cloud KMS. Our application servers pass the PDF through for signing but never hold the private key.

Encryption

Documents are encrypted with AES-256 at rest and TLS in transit. Connector credentials and other secrets are encrypted at rest.

Tenant isolation

Every request — from the dashboard or an API key — is resolved to a single workspace before it touches a document. One workspace can never read another’s files, fields or envelopes.

Audit trail

Each envelope carries an audit trail: who acted, when, from which IP address and approximate geolocation.

Envelope sent2026-07-18 09:12:04Z203.0.113.24San Francisco, US
Signed — Alexandra W-H2026-07-18 09:44:18Z198.51.100.7Oakland, US
Signed — Jordan Reyes2026-07-18 11:02:36Z192.0.2.61Berkeley, US
Sealed · PAdES2026-07-18 11:02:37Z—Cloud KMS

Example rows.

API keys & rate limits

API keys are shown once, in full, at creation. From then on we store only a SHA-256 hash — a lost key can be revoked and reissued, never recovered.

Per key
120 requests / min
Shared pool
20 / min across detect, fill, send

AI data handling

AppliFlo uses AI to detect fields and summarize documents. Our intent is that customer and CRM data is used to operate the service, not to train foundation models.

This policy is being finalized. It describes our current intent, not a contractual commitment yet.

Compliance

AppliFlo is designed to support ESIGN/UETA electronic-signature workflows. We do not claim certifications we do not hold; as formal programs progress, we will state their status plainly here.

Sub-processors & status

Our sub-processor list and status page will be linked here as they are published. For a security review, contact us.

Sign with confidence

Cryptographic signing, encryption, and a full audit trail — by default.

Drop a PDF here