A calm portrait in a modern office

Security

Clear security, not vague promises.

Electronic-signature products ask for trust. Here is what Bleinks actually does, without invented badges.

  • Who operates BleinksBleinks is a trading name of Vaitly Limited (Companies House 16814185, ICO ZC211167), registered office Mill House Penrhos Farm, Nantgarw, Cardiff, CF15 7UN. Privacy and ICO enquiries go to the Information Officer at info@vaitly.com.
  • Encryption in transitAll public traffic uses HTTPS with TLS 1.2 or later. Signing links are single-use tokens scoped to one document and expire with the document or within 30 days.
  • Encryption at restLive PDFs are stored in MinIO with server-side encryption and a key-management service. Signed PDFs are written as new immutable objects; a completed document is never overwritten.
  • Access controlSenders authenticate with Firebase Authentication. The API verifies Firebase ID tokens, including revocation checks. Public signing routes never accept sender credentials; they use the signing token and a one-time email code.
  • Tenant isolationDocument access is scoped in PostgreSQL. Signers only ever see the document they were invited to.
  • Audit loggingLegally relevant events are written to an append-only audit table. Application roles cannot update or delete those rows. Completed signatures produce an audit certificate alongside the sealed PDF.
  • Malware scanningEvery upload is scanned with ClamAV and must carry a genuine PDF header. Uploads that fail either check are rejected.
  • Backups and recoveryLocal daily backups plus off-site encrypted backups with restic to Wasabi object storage with object lock. Restore procedures are documented and exercised internally.
  • Retention and deletionDefault retention is 90 days after document completion, configurable per organisation. Account export and deletion are available to every account holder.
  • HostingApplication, database and hot object storage run on a Hetzner cloud server in a European data centre. We do not claim UK data residency.
Security, spoken

Subprocessors

HetznerCompute and hosting (EU)
Google FirebaseAuthentication
BrevoTransactional email
StripePayments
WasabiImmutable off-site backups

Your responsibilities

You remain responsible for choosing appropriate documents, verifying recipient identity where your use case requires it, and taking legal advice for high-value or regulated agreements.

Reporting a vulnerability

Email hello@bleinks.com with a subject line beginning [SECURITY]. We read every report.

Bleinks does not display certification badges it has not earned. Independent assessment results will be published here when complete.