Transport protection
HTTPS/TLS and HSTS protect browser-to-server traffic and keep connections on HTTPS.
AgreePack combines controls across transport, authentication, storage, integrity verification, and monitoring to protect consent documents and evidence. This page publishes the current implementation and its scope.
Rather than relying on one technology, controls are applied as data is transmitted, stored, and reviewed.
HTTPS/TLS and HSTS protect browser-to-server traffic and keep connections on HTTPS.
Email verification, password hashing, roles, and workspace-level data separation are used together.
SHA-256 enables later verification of PDFs, consent events, and evidence packs.
User files and database backups are handled in private locations, with database backups also stored off-server.
Extensions, MIME types, size, and post-storage hashes are checked, and ClamAV scans for malware.
Error monitoring, external availability monitoring, dependency scans, and passive web scans for production and staging run on a recurring schedule.
Hashing and encryption serve different purposes. The table states why each method is used and where it currently applies.
| Technology / method | Primary purpose | Current scope |
|---|---|---|
| HTTPS / TLS and HSTS | Encrypt traffic and keep connections on HTTPS | Web traffic between browsers and AgreePack |
| bcrypt | Protect passwords using a non-reversible method | Account passwords (hashing, not encryption) |
| AES-256-CBC + MAC | Application encryption with confidentiality and tamper detection | Data explicitly encrypted by the application, including consent-confirmation payloads and queued email contents |
| SHA-256 | Identify content and detect later changes | Source PDFs, hash-linked consent events, and evidence-pack files, manifests, and ZIP archives |
| SHA-256 token hashes | Avoid storing public URL tokens in plaintext in the database | Lookup tokens for consent links and member invitations |
| CSP, CSRF controls, and rate limits | Reduce web-attack and automated-request risks | Public consent pages, authentication, consent submission, file delivery, and related endpoints |
Each security technology has a distinct role and scope.
In addition to technical controls, the following policy covers information handling, access control, backups, and incident response.
As a service that handles consent collection and evidence organization, AgreePack takes technical and operational measures to reduce the risk of unauthorized access, leakage, loss, or damage.
Security controls are reviewed continuously as usage, system architecture, and risks change.
The service may handle the following information to provide its functions.
Depending on the document or input fields, sensitive information such as medical history, allergies, or medication status may be included. Do not collect information beyond what is necessary for the stated purpose.
AgreePack uses a Japan-based VPS provided by SAKURA internet Inc. for its production environment.
Access to servers, databases, and stored files is limited to what is necessary for service delivery, maintenance, incident response, security response, or legal compliance.
The operator accesses user documents or consent information only when required for requested support, troubleshooting, abuse or security investigations, or legal obligations.
Communications between browsers and AgreePack use HTTPS/TLS, while HSTS helps keep connections on HTTPS.
Account passwords are hashed with bcrypt. Selected confidential data, including consent-confirmation payloads and queued email contents, uses application encryption with AES-256-CBC and a MAC.
Source PDFs, consent events, and evidence packs use SHA-256 hashes so their integrity can be checked.
We use the following controls to reduce unauthorized access.
Users should not share passwords and should avoid reusing passwords from other services.
Access to documents, consent history, and member information is controlled by workspace membership and assigned permissions.
Users generally cannot view or operate on data belonging to other workspaces.
Consent pages are shared through URLs issued by users. If a URL is sent to the wrong person or posted publicly, an unintended third party may be able to access it.
Share consent-page URLs only with intended recipients and do not publish them on social media or public websites.
For procedures requiring strong identity verification, consider using a separate identity-verification or electronic-signature service together with AgreePack.
AgreePack stores operation history, audit logs, and access logs so that consent context, document updates, permission changes, and incidents can be reviewed later.
Access to logs is restricted, and logs are used for consent-record review, abuse prevention, troubleshooting, security investigations, and service improvement.
Backup and recovery procedures are maintained according to data importance and operational needs.
However, AgreePack does not guarantee complete restoration to the immediately preceding state or recovery of all data in every situation.
Users should export and retain evidence packs or other important records when necessary.
Production operations include the following measures.
AgreePack uses external providers to operate the service. Main providers include:
External services may be added, changed, or discontinued as features and operations evolve. See the Privacy Policy for information handling details.
If a security incident or suspected incident is identified, we respond as appropriate by:
If you discover a vulnerability, unintended disclosure, or other security concern, please contact us through the contact page.
Start with Free, then move to Standard when you need more. Keep your records easy to review later.