Skip to main content
LegalNerds
Trust Center · Security & Data Handling

Security & data handling

Each practice below is described against what we have actually built. For the electronic-signature evidence chain in full, see Electronic signatures.

Sensitive identifiers are encrypted, not stored in the clear

When a service you request requires a highly sensitive identifier — a Social Security Number or ITIN to obtain your business's EIN on an IRS filing — we never keep it in plaintext. It is encrypted with AES-256-GCM through a dedicated key that is not stored in the database; only the last four digits are kept in the clear for a masked display to our team. The full number is decrypted only at the moment it is needed to complete your filing, and every full decrypt writes an audit row recording who revealed it and when.

Private messaging

Messages between you and your matter are stored encrypted — the message body is ciphered at write and decrypted only on read for the parties entitled to it. We do not include message content in notification emails; the email tells you a message is waiting and links you to the secure channel.

First-party analytics — no third-party trackers, no IP retention

We build our own analytics; we do not embed Google Analytics or any third-party tracker, and nothing about your visit leaves for an outside host. We never store your IP address. Geographic labels come from coarse country/region/city signals only, and unique-visitor counts use an anonymous, daily-rotating, irreversible hash — a number that cannot be walked back to a person. Analytics runs on the marketing pages only, never inside your dashboard.

Identity step-up for high-stakes signatures

For the instrument classes most likely to be challenged later — prenuptial and postnuptial agreements, M&A instruments, and settlement agreements — signing requires a verified second factor: a one-time passcode texted to the signer's phone before the signature is composed. The number goes to our verification provider; only the masked last four digits and the verification time are kept on the record. The certificate for those documents is correspondingly stronger.

The retention lock — executed evidence cannot be destroyed

Once a document is signed, its evidence is non-deletable by design. A matter that carries an executed signature archives rather than deletes; the database itself refuses to remove a signed signature or a completed signing request, and the forensic columns of a signed record are frozen against any change — service-role included. Even account deletion cannot destroy signature evidence. (An optional per-tier retention schedule that would expire ordinary records after a set period is a planned future feature — today, executed records are kept.)

The formal commitments live in our Privacy Policy. Questions about a specific practice? Email support@legalnerds.com.