Skip to main content

Security

Last updated: 11 July 2026

We know you are trusting Squigggle with important documents and personal information. Here is how we protect them.

Encryption and tamper-evidence

Your documents are encrypted in transit (TLS) and at rest. Each signed document is cryptographically sealed using ECDSA P-256 signing and SHA-256 hashing, with a tamper-evident audit trail and certificate of completion, so that any later alteration can be detected.

Who can access your documents

We access the contents of your documents only where necessary to provide the Service — for example to convert, display, deliver and store them — to comply with a legal obligation, or as described in our Privacy Policy. Access to document contents is restricted to a small number of authorised personnel on a least-privilege, need-to-know basis, is logged, and is subject to binding confidentiality obligations. We do not read your documents for any other purpose, and we do not use your documents or their contents to train any machine-learning or artificial-intelligence model.

Infrastructure and hosting

Our platform is hosted primarily in the UK and EU — our database and document storage run in the AWS London region, and document conversion runs in the Google Cloud London region. Where a supplier processes personal data outside the UK or EU, we put appropriate safeguards in place (the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses). The full list of our sub-processors, with each one’s location and transfer safeguard, is on our Sub-processors page.

Backups and resilience

We take routine encrypted backups for business continuity and disaster recovery, isolated from our live environment.

Monitoring, testing and supplier due diligence

We log and monitor access to the Service, carry out regular security reviews, and perform data-protection due diligence on our sub-processors, binding them by written contract to obligations no less protective than our own.

Our security programme and certifications

We hold Cyber Essentials certification (the UK Government-backed scheme; certificate number 5dbdde12-a374-41ab-9347-99a5b3c70dbd). Our information security programme is aligned with the ISO 27001 framework and industry best practice.

Reporting a vulnerability

We welcome reports from security researchers. Please see our Responsible Disclosure policy, or email security@squigggle.io.

Document control

  • Version 2.0 — 11 July 2026 (current version)