---
title: Trust
description: What Docustay does about security, privacy and the law, said plainly, including what it does not claim.
---

# Trust

- [Security](/trust/security.md): What is in place today, and what is not.
- [Privacy](/trust/privacy.md): What we collect, who sees it, and how long it stays.
- [Legal validity](/trust/legal-validity.md): What kind of signature Docustay produces, in plain language.
- [Data handling](/trust/data-handling.md): Where your data lives, how it is protected, how long it stays, and how to take it with you or have it removed.
- [Signature standards](/trust/signature-standards.md): What is inside a signed PDF, and how anyone can check it.
- [Sub-processors](/trust/sub-processors.md): The companies that handle data so Docustay can run.

What we do not claim: no outside audit or certification, no health-privacy compliance, no qualified electronic signatures, no promise that any document is valid in any place.

## How to read these pages

Each page says what is in place today and, separately, what is not. Where something is not done, the page says so rather than leaving it out. If you are deciding whether Docustay fits a regulated or sensitive use, read the Not yet sections first; they are the part most pages leave out.

None of these pages is legal advice, and none promises a legal result for any document.

## What we do not claim

There is no outside audit and none is claimed. Docustay makes no claim about any health-privacy regime. There are no customer counts, logos or user quotes on this site, because none would be honest yet.

## Where the detail lives

Security covers sign-in, separation between workspaces, backups and reporting a problem. Privacy covers what is collected, who sees it and how long it is kept. Legal validity explains what kind of electronic signature Docustay produces. Sub-processors lists the companies that handle data so the service can run. The Terms, Privacy Policy and Data Processing Addendum hold the formal wording.

## Questions a buyer usually asks

Where is our data kept, who can see it, how do we get it out, what happens when we leave and how do we know a signed file was not changed? The Security, Privacy and Verify pages answer these in order, and the Contact page reaches a person for anything they do not.

## Reading the Not yet lists

Every Trust page ends with what is not in place. If a buyer, a board or a regulator asks about something, start there: it is the part of a page that tells you whether Docustay fits.

## Where we are open

Sub-processors lists every company that handles data so the service can run, the Data Processing Addendum is public, and the Verify page lets anyone check a sealed file without an account.

## Keep reading

- [Security](/trust/security)
- [Privacy](/trust/privacy)
- [Data handling](/trust/data-handling)
- [Signature standards](/trust/signature-standards)
- [Legal validity](/trust/legal-validity)
- [Sub-processors](/trust/sub-processors)
- [Terms](/legal/terms)
- [Data Processing Addendum](/legal/dpa)
