Security & Trust Preview

Security built for private document workflows.

SpeculaFree is designed to protect sensitive files, signing flows, secure exchanges, and document evidence with encryption-first architecture, access control, auditability, and privacy-led operational discipline.

Designed for businesses that need encrypted privacy, controlled access, and clear proof of document activity.

Protected document lifecycle
Sensitive Document
Client-Side Encryption
Encrypted Artifact Storage
Authorised Recipient Access
Signature Completion
Final Protected Document
Audit Evidence Report
Client-side encryption

Sensitive files are encrypted before being stored where zero-knowledge protection is active.

Audit-ready workflows

Document activity is recorded through lifecycle evidence.

Access-controlled sharing

Recipients only access the workflows they are authorised to use.

No sensitive secret logging

Passphrases, keys, plaintext documents, and decrypted bytes should never be logged.

What SpeculaFree protects

What we protect

SpeculaFree protects business document workflows where privacy, access control, and evidence matter. Our platform is being built around encrypted document handling, secure file exchange, signing workflows, final document delivery, and audit-ready activity records.

Encrypted document workflows

Upload, protect, share, sign, finalize, and download sensitive documents through a controlled workflow.

Secure file exchange

Send and receive files without relying on ordinary email attachments or uncontrolled download links.

Document signing

Prepare documents for signing, assign recipients, capture signature events, and produce signing evidence.

Audit evidence

Maintain document lifecycle proof without exposing document contents or secret material.

Security model

Our security model

SpeculaFree follows an encryption-first, privacy-led model. The aim is to reduce the amount of sensitive information the platform can access while still allowing businesses to manage, sign, exchange, and prove document activity.

1
Protect before storage

Where zero-knowledge encryption is used, files are encrypted before they are stored. This reduces exposure because stored files are not treated as ordinary readable documents.

2
Control access to workflows

Access to envelopes, recipients, signing actions, and downloads is controlled through authenticated workflow checks.

3
Preserve evidence without exposing secrets

SpeculaFree separates useful evidence from sensitive content. Audit events can record what happened without logging passphrases, encryption keys, plaintext files, decrypted bytes, or private document contents.

Encryption

Encryption and key handling

SpeculaFree is designed around the principle that sensitive customer documents should be encrypted before storage and handled through controlled cryptographic workflows. Where customer-held passphrases or client-side encryption are used, the goal is that SpeculaFree does not need access to plaintext document contents to store, route, sign, or deliver protected files.

Privacy principle

We do not want the platform to depend on reading customer documents in order to move them through a secure workflow.

Encrypted at rest

Stored files are handled as encrypted artifacts rather than ordinary readable documents.

Encrypted in transit

Data is transmitted over secure HTTPS connections between the browser, application, backend functions, and storage services.

Client-side protection

Where supported by the workflow, encryption happens before upload so sensitive material is protected before it leaves the user’s browser.

No secret logging

Security diagnostics should never include passphrases, tokens, private keys, ciphertext bytes, decrypted bytes, plaintext PDFs, or sensitive personal data.

Document lifecycle

Document lifecycle security

A secure document workflow is not only about storing files. It is about controlling every stage of the document lifecycle, from upload to final evidence.

UploadEncryptStoreAssignSendSignFinalizeDownloadAudit
1
Upload

A user uploads a document into a controlled workflow.

2
Encrypt

The document is encrypted before being stored where zero-knowledge protection is active.

3
Store

The encrypted artifact is stored with metadata needed to route and recover the protected workflow.

4
Assign

Recipients and signature fields are assigned to the envelope.

5
Send

Authorised recipients receive access to the relevant signing workflow.

6
Sign

Signature events are captured and attached to the document lifecycle.

7
Finalize

The completed document is finalized and protected as the final artifact.

8
Download

Authorised users can retrieve the final encrypted artifact through the approved download path.

9
Audit

Lifecycle events are recorded to prove what happened without exposing secret material.

Access control

Access control

SpeculaFree uses access control to limit who can create, send, sign, finalize, view, and download protected documents. Access is based on authenticated users, envelope ownership, recipient assignment, and workflow-specific authorisation checks.

Envelope ownership

Document owners control the workflows they create.

Recipient validation

Recipients should only access envelopes where they have been assigned to participate.

Role-based actions

Sensitive actions such as sending, finalizing, and downloading are restricted to authorised users and valid workflow states.

Controlled backend functions

Backend functions enforce workflow rules before documents or metadata are updated.

Audit evidence

Audit trails and evidence

Security-conscious businesses need more than encryption. They need proof. SpeculaFree is designed to capture document lifecycle evidence so customers can understand who did what, when it happened, and which workflow state changed.

Envelope created
Document uploaded
Recipients assigned
Signature fields placed
Envelope sent
Recipient accessed signing flow
Signature completed
Final artifact created
Final document hash recorded
Download event captured
Access denied event recorded
Audit evidence should prove activity without exposing the protected document itself.

Logging discipline

What we do not log

Security logs are useful only when they do not create new risk. SpeculaFree’s diagnostic and audit philosophy is to capture operational proof while avoiding sensitive secrets and protected content.

Safe to record
  • Envelope ID
  • Workflow status
  • Authorisation result
  • Timestamps
  • Event type
  • Content type
  • Byte length
  • Finalization status
  • Masked recipient reference
  • Error category
Not safe to record
  • Passphrases
  • Private keys
  • Access tokens
  • Plaintext PDFs
  • Decrypted document bytes
  • Ciphertext bytes
  • Full sensitive document contents
  • Raw personal data where not required

Privacy

Privacy by design

SpeculaFree is built with privacy minimisation in mind. The platform should only collect and retain the information required to operate secure document workflows, provide access control, support audit evidence, and meet legal or operational obligations.

Data minimisation

We aim to avoid collecting unnecessary customer data.

Purpose limitation

Workflow data is used to operate protected document services, not to expose or exploit customer content.

Controlled retention

Retention rules should be defined for documents, metadata, audit records, and customer accounts.

Deletion support

Customers should be able to request deletion or retention handling according to applicable requirements.

Secure development

How we build securely

SpeculaFree’s build process is based on controlled change, evidence-led debugging, and minimal-risk patching. Security-sensitive flows are audited before changes are made, and fixes are kept as small as possible to avoid regressions in encryption, signing, storage, finalization, and download paths.

Audit before patching

We identify the first broken contract before editing security-sensitive code.

Small patch surface

We avoid broad refactors in protected workflows unless evidence proves they are necessary.

Contract protection

Core workflow contracts are preserved across upload, signing, delivery, finalization, and download.

Regression testing

Critical paths are retested after change, including signing, finalization, old documents, partial signing, and wrong-passphrase behaviour.

Infrastructure

Infrastructure and storage

SpeculaFree uses managed application infrastructure and encrypted object storage patterns to support secure document workflows. Our architecture separates application logic, workflow metadata, encrypted artifacts, and access-controlled backend operations.

Application layer

Handles authenticated user workflows, dashboard access, envelope preparation, and secure document actions.

Controlled server operations

Perform controlled workflow operations such as upload authorisation, envelope updates, finalization checks, and secure download preparation.

Encrypted storage

Stores protected document artifacts separately from ordinary application data.

Metadata separation

Workflow metadata is separated from protected document contents wherever possible.

Compliance roadmap

Compliance and assurance roadmap

SpeculaFree is building toward recognised security and privacy assurance standards. Our public security page reflects our current security model and our direction of travel. Formal certifications and independent reports will be published or made available as they are completed.

Area
Security documentation
Status
In progress
Meaning
Public and internal security documentation is being developed.
Area
GDPR documentation
Status
In progress
Meaning
Privacy, data processing, and retention materials are being prepared.
Area
External penetration test
Status
Planned
Meaning
Independent security testing will be used to validate key workflows.
Area
Cyber Essentials
Status
Planned
Meaning
UK baseline cyber certification target.
Area
ISO 27001 readiness
Status
Future phase
Meaning
Information security management system target.
Area
SOC 2 readiness
Status
Future phase
Meaning
SaaS control assurance target for enterprise buyers.

We are building toward these assurance standards. We do not claim formal certification until certification has been completed.

Due diligence

Security documents available for review

For qualified customers, partners, or enterprise security reviews, SpeculaFree can provide additional security and privacy documentation under request or NDA where appropriate.

Security Overview
Encryption Model Summary
Zero-Knowledge Architecture Summary
Data Flow Overview
Access Control Summary
Audit Trail Summary
Data Processing Agreement
Subprocessor List
Incident Response Summary
Security Questionnaire Responses
Penetration Test Summary, when available
Certification Evidence, when available

FAQ

Security FAQ

Security review

Need to review SpeculaFree for your organisation?

We can provide additional security, privacy, and compliance information for qualified business reviews. Request our security documents or contact us for enterprise due diligence.

SpeculaFree is not built around ordinary document storage. It is built around protected document workflows: encryption, controlled access, signing evidence, final artifact protection, and audit-ready activity records.