ESIGN & UETA
Agreements meet the U.S. ESIGN Act and the Uniform Electronic Transactions Act — the same legal framework DocuSign and Adobe Sign rely on. Signature payload, intent, attribution, and consent are captured on every signed agreement.
Security & compliance
Every agreement signed through NDAKit ships with a tamper-evident audit trail, state-specific compliance overlays, and infrastructure from SOC 2-certified providers. Below: exactly how, and exactly what we do not yet have.
Built on SOC 2-certified infrastructure. Cloudflare (SOC 2 Type II + ISO 27001 + PCI-DSS) handles compute, storage, and edge delivery. Brevo (SOC 2 Type II + GDPR) handles transactional email and SMS. Stripe (SOC 2 Type II + PCI-DSS Level 1) handles payments.
An independent NDAKit SOC 2 Type II audit is pursued when enterprise customers require it. If you need a dedicated NDAKit SOC 2 report for procurement, email security@ndakit.com and we will scope the audit on your timeline.
Email us about enterprise SOC 2Pillars
Agreements meet the U.S. ESIGN Act and the Uniform Electronic Transactions Act — the same legal framework DocuSign and Adobe Sign rely on. Signature payload, intent, attribution, and consent are captured on every signed agreement.
Compliance language for CA, NY, NJ, WA, IL, and OR is auto- applied based on signer location. No manual template forking or legal-review-per-state required.
Defend Trade Secrets Act (18 U.S.C. §1833(b)) whistleblower notice is automatically inserted in NDAs and contractor agreements covering trade secret protections.
IP address, geolocation, timestamps, document hash, browser fingerprint, and signature payload — exportable as a single evidence package, admissible in U.S. courts.
State overlays
When the recipient's address resolves to one of these states, NDAKit automatically applies the carve-out language below to the generated agreement. The signed PDF flags which overlays were triggered.
Excludes restrictions on disclosure of unlawful workplace conduct (CA Code §12964.5). Excludes whistleblower retaliation clauses prohibited by Cal. Lab. Code §1102.5.
Carve-outs for harassment and discrimination disclosure per NY CPLR §5003-B. Recipients retain right to discuss compensation per NY Lab. Law §215.
NJ S121 (2019) — NDAs cannot conceal details of discrimination, retaliation, or harassment claims. Auto-applied to all NJ-jurisdiction NDAs.
Silenced No More Act — non-disclosure provisions cannot prevent disclosure of conduct that is illegal under WA or federal law.
Workplace Transparency Act overlay — employees retain right to make truthful statements about unlawful employment practices.
Workplace Fairness Act — restrictions on settlement and severance NDAs covering discrimination/harassment claims.
Encryption
All API and signing traffic is encrypted with TLS 1.3 (downgrade to TLS 1.2 only). HSTS preload list, perfect forward secrecy, and modern cipher suites only.
Documents, signatures, and audit data encrypted at rest with AES-256. Stored in Cloudflare R2 + D1 with per-tenant access controls and tenant-scoped API keys.
Each signed PDF carries an embedded SHA-256 hash and signed HTML twin. Any post-signature edit invalidates the hash — publicly verifiable from the audit trail page.
Subprocessors
NDAKit deliberately runs on a small, audited stack. Every subprocessor below is SOC 2 / PCI-DSS / GDPR certified.
We pursue an independent SOC 2 Type II audit when enterprise customers require it. Email security@ndakit.com or schedule a call below to scope it on your procurement timeline.