Security & compliance

Court-admissible by default. Built for the real world.

Every agreement signed through NDAKit ships with a tamper-evident audit trail, state-specific compliance overlays, and infrastructure from SOC 2-certified providers. Below: exactly how, and exactly what we do not yet have.

SOC 2 — the honest version

Built on SOC 2-certified infrastructure. Cloudflare (SOC 2 Type II + ISO 27001 + PCI-DSS) handles compute, storage, and edge delivery. Brevo (SOC 2 Type II + GDPR) handles transactional email and SMS. Stripe (SOC 2 Type II + PCI-DSS Level 1) handles payments.

An independent NDAKit SOC 2 Type II audit is pursued when enterprise customers require it. If you need a dedicated NDAKit SOC 2 report for procurement, email security@ndakit.com and we will scope the audit on your timeline.

Email us about enterprise SOC 2

Pillars

Four pillars, one signed PDF.

ESIGN & UETA

Agreements meet the U.S. ESIGN Act and the Uniform Electronic Transactions Act — the same legal framework DocuSign and Adobe Sign rely on. Signature payload, intent, attribution, and consent are captured on every signed agreement.

Recipient-state overlays

Compliance language for CA, NY, NJ, WA, IL, and OR is auto- applied based on signer location. No manual template forking or legal-review-per-state required.

DTSA notice baked in

Defend Trade Secrets Act (18 U.S.C. §1833(b)) whistleblower notice is automatically inserted in NDAs and contractor agreements covering trade secret protections.

Audit trail

IP address, geolocation, timestamps, document hash, browser fingerprint, and signature payload — exportable as a single evidence package, admissible in U.S. courts.

State overlays

Six states with mandatory carve-outs. Auto-applied.

When the recipient's address resolves to one of these states, NDAKit automatically applies the carve-out language below to the generated agreement. The signed PDF flags which overlays were triggered.

CACalifornia

Excludes restrictions on disclosure of unlawful workplace conduct (CA Code §12964.5). Excludes whistleblower retaliation clauses prohibited by Cal. Lab. Code §1102.5.

NYNew York

Carve-outs for harassment and discrimination disclosure per NY CPLR §5003-B. Recipients retain right to discuss compensation per NY Lab. Law §215.

NJNew Jersey

NJ S121 (2019) — NDAs cannot conceal details of discrimination, retaliation, or harassment claims. Auto-applied to all NJ-jurisdiction NDAs.

WAWashington

Silenced No More Act — non-disclosure provisions cannot prevent disclosure of conduct that is illegal under WA or federal law.

ILIllinois

Workplace Transparency Act overlay — employees retain right to make truthful statements about unlawful employment practices.

OROregon

Workplace Fairness Act — restrictions on settlement and severance NDAs covering discrimination/harassment claims.

Encryption

TLS 1.3 in transit. AES-256 at rest.

In transit

All API and signing traffic is encrypted with TLS 1.3 (downgrade to TLS 1.2 only). HSTS preload list, perfect forward secrecy, and modern cipher suites only.

At rest

Documents, signatures, and audit data encrypted at rest with AES-256. Stored in Cloudflare R2 + D1 with per-tenant access controls and tenant-scoped API keys.

Tamper sealing

Each signed PDF carries an embedded SHA-256 hash and signed HTML twin. Any post-signature edit invalidates the hash — publicly verifiable from the audit trail page.

Subprocessors

Four certified providers. Nothing else.

NDAKit deliberately runs on a small, audited stack. Every subprocessor below is SOC 2 / PCI-DSS / GDPR certified.

Provider
Role
Certifications
Cloudflare
Compute, storage, edge delivery, DNS, WAF
SOC 2 Type II · ISO 27001 · PCI-DSS · GDPR
Brevo
Transactional email + SMS notifications
SOC 2 Type II · GDPR · ISO 27001
Stripe
Payment processing (deposits, full-pay)
SOC 2 Type II · PCI-DSS Level 1 · GDPR
PayPal
Optional payment method for deposits
SOC 2 · PCI-DSS Level 1 · GDPR

Need an NDAKit-specific SOC 2 report?

We pursue an independent SOC 2 Type II audit when enterprise customers require it. Email security@ndakit.com or schedule a call below to scope it on your procurement timeline.