AgreePack Evidence, made clear.
Free templates Use cases How it works Features Evidence pack Pricing FAQ
Log in Start for free JA EN
SECURITY

Our approach to security

AgreePack combines controls across transport, authentication, storage, integrity verification, and monitoring to protect consent documents and evidence. This page publishes the current implementation and its scope.

Tsugaru Design Studio Last updated: 2026.08.23

Security at a glance

Rather than relying on one technology, controls are applied as data is transmitted, stored, and reviewed.

TRANSPORT

Transport protection

HTTPS/TLS and HSTS protect browser-to-server traffic and keep connections on HTTPS.

IDENTITY

Authentication and authorization

Email verification, password hashing, roles, and workspace-level data separation are used together.

INTEGRITY

Document and evidence integrity

SHA-256 enables later verification of PDFs, consent events, and evidence packs.

STORAGE

Private storage and backups

User files and database backups are handled in private locations, with database backups also stored off-server.

FILES

File validation

Extensions, MIME types, size, and post-storage hashes are checked, and ClamAV scans for malware.

OPERATIONS

Monitoring and continuous checks

Error monitoring, external availability monitoring, dependency scans, and passive web scans for production and staging run on a recurring schedule.

Security technologies and current scope

Hashing and encryption serve different purposes. The table states why each method is used and where it currently applies.

Technology / method Primary purpose Current scope
HTTPS / TLS and HSTS Encrypt traffic and keep connections on HTTPS Web traffic between browsers and AgreePack
bcrypt Protect passwords using a non-reversible method Account passwords (hashing, not encryption)
AES-256-CBC + MAC Application encryption with confidentiality and tamper detection Data explicitly encrypted by the application, including consent-confirmation payloads and queued email contents
SHA-256 Identify content and detect later changes Source PDFs, hash-linked consent events, and evidence-pack files, manifests, and ZIP archives
SHA-256 token hashes Avoid storing public URL tokens in plaintext in the database Lookup tokens for consent links and member invitations
CSP, CSRF controls, and rate limits Reduce web-attack and automated-request risks Public consent pages, authentication, consent submission, file delivery, and related endpoints

Scope of these statements

Each security technology has a distinct role and scope.

  • AES-256-CBC applies only to data explicitly encrypted by the application. It does not mean that all stored data uses the same application-layer encryption.
  • SHA-256 is used to detect and verify content changes. It is not encryption and does not mean that data is impossible to alter.
  • Dependency scans and passive web scans are continuous automated checks; they do not constitute a completed independent third-party security assessment.
  • These controls are intended to reduce risk and do not guarantee that a security incident can never occur.

Security management policy

In addition to technical controls, the following policy covers information handling, access control, backups, and incident response.

1. Basic policy

As a service that handles consent collection and evidence organization, AgreePack takes technical and operational measures to reduce the risk of unauthorized access, leakage, loss, or damage.

Security controls are reviewed continuously as usage, system architecture, and risks change.

2. Main information handled

The service may handle the following information to provide its functions.

  • Account names, email addresses, and workspace information
  • Uploaded PDF documents and document version information
  • Information entered by consent subjects, including names, contact details, and confirmations
  • Consent timestamps, IP addresses, User-Agent data, and operation history
  • Audit logs for members, permissions, document updates, and evidence-pack exports
  • Plan, billing status, and information required for Stripe integration
  • Information required for support, incident investigation, and abuse prevention

Depending on the document or input fields, sensitive information such as medical history, allergies, or medication status may be included. Do not collect information beyond what is necessary for the stated purpose.

3. Server and data storage

AgreePack uses a Japan-based VPS provided by SAKURA internet Inc. for its production environment.

Access to servers, databases, and stored files is limited to what is necessary for service delivery, maintenance, incident response, security response, or legal compliance.

The operator accesses user documents or consent information only when required for requested support, troubleshooting, abuse or security investigations, or legal obligations.

4. Transport and cryptographic protection

Communications between browsers and AgreePack use HTTPS/TLS, while HSTS helps keep connections on HTTPS.

Account passwords are hashed with bcrypt. Selected confidential data, including consent-confirmation payloads and queued email contents, uses application encryption with AES-256-CBC and a MAC.

Source PDFs, consent events, and evidence packs use SHA-256 hashes so their integrity can be checked.

5. Authentication and access control

We use the following controls to reduce unauthorized access.

  • Login authentication and email verification
  • Password storage using a non-reversible hashing method
  • Workspace- and role-based access control
  • Separation of user-facing and operator-facing functions
  • Additional access restrictions for operator functions
  • Logging of important operations performed with authenticated accounts

Users should not share passwords and should avoid reusing passwords from other services.

6. Workspace data separation

Access to documents, consent history, and member information is controlled by workspace membership and assigned permissions.

Users generally cannot view or operate on data belonging to other workspaces.

7. Handling consent-page URLs

Consent pages are shared through URLs issued by users. If a URL is sent to the wrong person or posted publicly, an unintended third party may be able to access it.

Share consent-page URLs only with intended recipients and do not publish them on social media or public websites.

For procedures requiring strong identity verification, consider using a separate identity-verification or electronic-signature service together with AgreePack.

8. Operation history and audit logs

AgreePack stores operation history, audit logs, and access logs so that consent context, document updates, permission changes, and incidents can be reviewed later.

Access to logs is restricted, and logs are used for consent-record review, abuse prevention, troubleshooting, security investigations, and service improvement.

9. Backups and recovery

Backup and recovery procedures are maintained according to data importance and operational needs.

However, AgreePack does not guarantee complete restoration to the immediately preceding state or recovery of all data in every situation.

Users should export and retain evidence packs or other important records when necessary.

10. Secure operations

Production operations include the following measures.

  • Preventing internal error details and debug information from being displayed publicly
  • Disabling unnecessary public, debug, and administrative functions
  • Updating operating systems, Laravel, PHP, and Composer packages
  • Reviewing errors, incidents, and unusual usage
  • Managing credentials, secret keys, API keys, and other secrets appropriately
  • Investigating, correcting, and preventing recurrence when security issues are identified

11. External services

AgreePack uses external providers to operate the service. Main providers include:

  • SAKURA internet Inc.: servers, networks, and infrastructure
  • Cloudflare: DNS, reverse proxy, CDN, WAF, and DDoS mitigation
  • Stripe: paid-plan payments, billing, and subscription management
  • Google Analytics: analysis of public website usage
  • Sentry: error and incident detection and investigation
  • UptimeRobot: external monitoring of public endpoints and scheduled tasks, plus the service-status page
  • Resend: delivery of authentication, notification, and support emails

External services may be added, changed, or discontinued as features and operations evolve. See the Privacy Policy for information handling details.

12. Security incident response

If a security incident or suspected incident is identified, we respond as appropriate by:

  • Taking immediate steps to contain the impact
  • Identifying affected information, users, and scope
  • Investigating the cause and restoring service
  • Notifying affected users
  • Making legally required reports or notices
  • Implementing recurrence-prevention measures

13. Security contact

If you discover a vulnerability, unintended disclosure, or other security concern, please contact us through the contact page.

Trust Center and reporting contact

Make AgreePack simpler.

Start with Free, then move to Standard when you need more. Keep your records easy to review later.

Start for free Log in
© 2026 AgreePack
Features Terms Privacy Policy Security Trust Center Service Status Legal Position Legal Notice Contact