Trust

Built to satisfy the people who audit you.

Pactivo is built for regulated work — legal, accountancy, property, immigration. Compliance is not a page we wrote after the fact; it is the product. Here is exactly how it holds up.

UK data residency
Documents stored and processed in the UK. GDPR by default.
Tamper-evident audit
SHA-256 chained events, sealed and verifiable on completion.

Compliance tiers under UK eIDAS

Pactivo ships Simple Electronic Signature today, with Advanced and Qualified tiers on a public roadmap.

Live
SESSimple

Intent and consent captured, with a full audit trail. Valid and admissible for the majority of commercial agreements.

Audit trail capture
Optional identity binding
On roadmap
AESAdvanced

Uniquely linked to a verified identity via Certivus, with tamper detection on the signed document.

Certivus identity binding
Document tamper detection
Exploring
QESQualified

Backed by a qualified certificate from a trust service provider — the legal equivalent of a handwritten signature.

QTSP partnership
Qualified certificates
The proof

Every signature carries its own evidence.

The audit trail is not a download you hope never to need. It is a first-class, shareable record — every event timestamped, every device logged, every verification step recorded, the whole chain sealed with SHA-256.

Who and when
Timestamps, IPs, devices for every event.
Verification on record
Every one-time passcode check captured as it happened.
Sealed & shareable
A public URL and a signed PDF, tamper-evident.

Security overview

Encryption everywhere
TLS 1.3 in transit, AES-256 at rest across the database and document storage.
UK data residency
Documents, signatures and audit trails are stored and processed in the UK — AWS London (eu-west-2). Transactional email is delivered by Resend (EU/US); the privacy policy sets out the detail.
Tamper-evidence
Each event is hash-chained. A single altered byte breaks the seal, visibly.
Access control
Role-based access, and every record scoped to its organisation twice over — row-level security in the database and an explicit check in application code.
Secrets are hashed
Signing links, API keys and one-time passcodes are stored only as hashes. Raw values are shown once and are never recoverable.
Deletion and export
Handled on request rather than self-serve today. Email us and we action it within 30 days.

Sub-processors

Every third party that processes personal data on our behalf. This is the same list as the one in our privacy policy — they are generated from a single source so they cannot disagree.

Supabase (on AWS)Database, document storage, edge compute
UK — London (eu-west-2)
VercelHosting and delivery of the web application
Global edge
ResendTransactional email delivery
EU / US
CloudflareTurnstile bot protection
Global edge
Plausible AnalyticsCookieless marketing-site analytics
EU

Planned — not yet in use

These are not integrated and process no customer data today. Each moves into the list above, with notice, before it handles anything.

CertivusIdentity verification (AML/KYC), for the planned Advanced (AES) tier
UK

“Will it hold up?” is the only question that matters. The audit trail answers it.

A typed name proves a click. A Pactivo signature carries a sealed chain of evidence — who signed, from where, when, and what they agreed to — and a record you can hand to a regulator without explanation.

Start signing