Security

What we do — and what we don't claim

Plain descriptions of how Mudra protects your signatures, documents and team data today.

What we do

Encrypted in transit
Everything travels over HTTPS (TLS), and browsers are told to keep using it.
Your account only sees its own data
Signatures, documents, team members, campaigns and uploads are protected by database access rules, so one account cannot read or change another's. The few things that are meant to be public are public on purpose: the signature images embedded in your emails, and a signing link for whoever you send it to.
Uploads are locked to their owner
Logos and banners are stored in a per-account folder. Only the account that uploaded a file can replace, delete or list its files. Anyone with a file's link can view it — that is what lets it show up in an email.
Signing links are secrets
Each signer gets a long random link. Anyone who holds it can sign as that person, so it should be treated like a password and sent only to them. Signing pages send no referrer and load no analytics.
Signing records are written by the server
When someone signs, the database records the time and the IP address and browser it saw — not values sent from the signer's browser. When the last person signs, it takes a fingerprint (SHA-256) of the finished record: the original upload, every field value and the signer list. Completed documents are sealed against edits through the app, and the sender can check at any time that the record still matches its fingerprint.
Deploying to a company's Gmail is gated
Pushing signatures into mailboxes needs a Google Workspace super-admin to authorise Mudra once, limited to signature settings (it cannot read mail). We then switch it on company by company and name that company's deployment admin; only they, and people they add, can deploy. Every deployment is logged before any mailbox is touched.
Analytics are opt-in
Google Analytics and Microsoft Clarity stay off until you accept them, and they never run on signing pages or email click-through links.
Sign-in
Email and password or Google sign-in, with email confirmation. Passwords are handled by our authentication provider and never stored by us in readable form.

What we don't claim

  • No SOC 2 or ISO 27001 certification. Those are goals, not claims.
  • No independent penetration test yet. We have run our own security reviews and fixed what they found, but that is not the same thing.
  • Mudra Sign is an audit record, not a qualified or PKI digital signature, and it does not verify who a signer is. Anyone with the link can sign as that person.
  • As the operator of a hosted service, we have technical access to the database for support and maintenance. Our admin screen shows account facts only (email, sign-in method, plan, counts), never the content of your signatures or documents.

Where your data lives

The database, sign-in and file storage are hosted by Supabase and the application by Vercel. If you accept analytics, Google and Microsoft also receive usage data. The full list of service providers is in our Privacy Policy and Data Processing Addendum.

Found a problem?

If you think you've found a security issue, please email avinash@nashenterprises.in with what you found and how to reproduce it. We aim to reply within 3 business days. Please don't access other people's data or disrupt the service while testing.