Security & evidence
Built like a system of record, because it is one
A signed waiver only matters on the worst day of your year. Here is exactly how FlatWaivermakes sure the record holds up on it — and why you're never locked in.
How the evidence holds up
Tamper-evident by construction
Every signed waiver is rendered to PDF exactly once, at the moment of signing. A SHA-256 fingerprint of the document is stamped into the PDF and recorded separately in our database. Recompute the hash of the file at any time — in court, for an insurer, years later — and compare. If a single byte had changed, the hashes wouldn't match.
Immutable records and waiver text
Signed records are append-only: not even we can edit or delete them — the database itself rejects the change. Waiver text is versioned the same way, so every signature is permanently pinned to the exact wording the signer saw, plus the consent statement they agreed to, their IP, device, and timestamp.
Encrypted and isolated
All data is encrypted in transit (TLS) and at rest. Your organization's records are isolated at the database level with row-level security — one business can never query another's data. Signed PDFs and signature images live in private storage, served only through short-lived signed URLs to authenticated members of your business.
Your data is never hostage
Export everything, any time: a CSV of all records and bulk PDF downloads of every signed waiver — in the app, with no volume caps and no “storage plan” fee. Viewing and exporting your existing records is never gated on your subscription. Cancel, and your signed waivers stay viewable and downloadable.
What every signed waiver captures
Far more than a paper form — a purpose-built evidence bundle attached to each signature:
- The signer's full legal name
- Email address (when collected)
- Date of birth (where age matters)
- The drawn or typed signature image
- Guardian name, relationship, and signature (for minors)
- Any custom fields you configured (medical conditions, emergency contact, …)
- The exact consent statement they agreed to, stored verbatim
- The exact waiver version text they signed
- IP address and browser / device (user agent)
- A UTC timestamp and the signing channel (link, QR, or kiosk)
- A SHA-256 integrity hash of the final PDF
Your records, your custody
While your account is active
Every signed waiver is retained — immutable, searchable, and exportable at any time.
If you cancel
Your records stay viewable and downloadable. A lapsed subscription only pauses new signatures; it never locks your existing legal documents.
On request or account closure
We delete your organization's data when you ask us to.
Where your data lives
FlatWaiver runs on infrastructure from providers that maintain SOC 2 Type II attestations (Supabase and Vercel). These are the subprocessors that handle data on our behalf:
| Provider | What it does |
|---|---|
| Supabase | Database, authentication, and encrypted file storage |
| Vercel | Application hosting and content delivery |
| Anthropic (Claude) | AI conversion of an uploaded waiver PDF into a digital form |
| Resend | Transactional email — signed copies and notifications |
| Creem | Subscription billing — we never see or store card numbers |
| Cloudflare Turnstile | Bot protection on public signing pages |
Legal recognition
Electronic signatures collected through FlatWaiver are recognized in the United States under the federal ESIGN Act and UETA. Every signer affirmatively consents before signing, and the exact consent text is stored with the record. For the full picture of what makes a digital waiver enforceable, see are digital waivers legally binding?
Got a security questionnaire?
Questions about our data handling, or a specific compliance requirement for your vendor review? We answer these personally.
This page is not legal advice; have a lawyer review your waiver text.