Security & Trust Preview
Security built for private document workflows.
SpeculaFree is designed to protect sensitive files, signing flows, secure exchanges, and document evidence with encryption-first architecture, access control, auditability, and privacy-led operational discipline.
Designed for businesses that need encrypted privacy, controlled access, and clear proof of document activity.
Sensitive files are encrypted before being stored where zero-knowledge protection is active.
Document activity is recorded through lifecycle evidence.
Recipients only access the workflows they are authorised to use.
Passphrases, keys, plaintext documents, and decrypted bytes should never be logged.
What SpeculaFree protects
What we protect
SpeculaFree protects business document workflows where privacy, access control, and evidence matter. Our platform is being built around encrypted document handling, secure file exchange, signing workflows, final document delivery, and audit-ready activity records.
Upload, protect, share, sign, finalize, and download sensitive documents through a controlled workflow.
Send and receive files without relying on ordinary email attachments or uncontrolled download links.
Prepare documents for signing, assign recipients, capture signature events, and produce signing evidence.
Maintain document lifecycle proof without exposing document contents or secret material.
Security model
Our security model
SpeculaFree follows an encryption-first, privacy-led model. The aim is to reduce the amount of sensitive information the platform can access while still allowing businesses to manage, sign, exchange, and prove document activity.
Where zero-knowledge encryption is used, files are encrypted before they are stored. This reduces exposure because stored files are not treated as ordinary readable documents.
Access to envelopes, recipients, signing actions, and downloads is controlled through authenticated workflow checks.
SpeculaFree separates useful evidence from sensitive content. Audit events can record what happened without logging passphrases, encryption keys, plaintext files, decrypted bytes, or private document contents.
Encryption
Encryption and key handling
SpeculaFree is designed around the principle that sensitive customer documents should be encrypted before storage and handled through controlled cryptographic workflows. Where customer-held passphrases or client-side encryption are used, the goal is that SpeculaFree does not need access to plaintext document contents to store, route, sign, or deliver protected files.
Privacy principle
We do not want the platform to depend on reading customer documents in order to move them through a secure workflow.
Stored files are handled as encrypted artifacts rather than ordinary readable documents.
Data is transmitted over secure HTTPS connections between the browser, application, backend functions, and storage services.
Where supported by the workflow, encryption happens before upload so sensitive material is protected before it leaves the user’s browser.
Security diagnostics should never include passphrases, tokens, private keys, ciphertext bytes, decrypted bytes, plaintext PDFs, or sensitive personal data.
Document lifecycle
Document lifecycle security
A secure document workflow is not only about storing files. It is about controlling every stage of the document lifecycle, from upload to final evidence.
A user uploads a document into a controlled workflow.
The document is encrypted before being stored where zero-knowledge protection is active.
The encrypted artifact is stored with metadata needed to route and recover the protected workflow.
Recipients and signature fields are assigned to the envelope.
Authorised recipients receive access to the relevant signing workflow.
Signature events are captured and attached to the document lifecycle.
The completed document is finalized and protected as the final artifact.
Authorised users can retrieve the final encrypted artifact through the approved download path.
Lifecycle events are recorded to prove what happened without exposing secret material.
Access control
Access control
SpeculaFree uses access control to limit who can create, send, sign, finalize, view, and download protected documents. Access is based on authenticated users, envelope ownership, recipient assignment, and workflow-specific authorisation checks.
Document owners control the workflows they create.
Recipients should only access envelopes where they have been assigned to participate.
Sensitive actions such as sending, finalizing, and downloading are restricted to authorised users and valid workflow states.
Backend functions enforce workflow rules before documents or metadata are updated.
Audit evidence
Audit trails and evidence
Security-conscious businesses need more than encryption. They need proof. SpeculaFree is designed to capture document lifecycle evidence so customers can understand who did what, when it happened, and which workflow state changed.
Logging discipline
What we do not log
Security logs are useful only when they do not create new risk. SpeculaFree’s diagnostic and audit philosophy is to capture operational proof while avoiding sensitive secrets and protected content.
- Envelope ID
- Workflow status
- Authorisation result
- Timestamps
- Event type
- Content type
- Byte length
- Finalization status
- Masked recipient reference
- Error category
- Passphrases
- Private keys
- Access tokens
- Plaintext PDFs
- Decrypted document bytes
- Ciphertext bytes
- Full sensitive document contents
- Raw personal data where not required
Privacy
Privacy by design
SpeculaFree is built with privacy minimisation in mind. The platform should only collect and retain the information required to operate secure document workflows, provide access control, support audit evidence, and meet legal or operational obligations.
We aim to avoid collecting unnecessary customer data.
Workflow data is used to operate protected document services, not to expose or exploit customer content.
Retention rules should be defined for documents, metadata, audit records, and customer accounts.
Customers should be able to request deletion or retention handling according to applicable requirements.
Secure development
How we build securely
SpeculaFree’s build process is based on controlled change, evidence-led debugging, and minimal-risk patching. Security-sensitive flows are audited before changes are made, and fixes are kept as small as possible to avoid regressions in encryption, signing, storage, finalization, and download paths.
We identify the first broken contract before editing security-sensitive code.
We avoid broad refactors in protected workflows unless evidence proves they are necessary.
Core workflow contracts are preserved across upload, signing, delivery, finalization, and download.
Critical paths are retested after change, including signing, finalization, old documents, partial signing, and wrong-passphrase behaviour.
Infrastructure
Infrastructure and storage
SpeculaFree uses managed application infrastructure and encrypted object storage patterns to support secure document workflows. Our architecture separates application logic, workflow metadata, encrypted artifacts, and access-controlled backend operations.
Handles authenticated user workflows, dashboard access, envelope preparation, and secure document actions.
Perform controlled workflow operations such as upload authorisation, envelope updates, finalization checks, and secure download preparation.
Stores protected document artifacts separately from ordinary application data.
Workflow metadata is separated from protected document contents wherever possible.
Compliance roadmap
Compliance and assurance roadmap
SpeculaFree is building toward recognised security and privacy assurance standards. Our public security page reflects our current security model and our direction of travel. Formal certifications and independent reports will be published or made available as they are completed.
We are building toward these assurance standards. We do not claim formal certification until certification has been completed.
Due diligence
Security documents available for review
For qualified customers, partners, or enterprise security reviews, SpeculaFree can provide additional security and privacy documentation under request or NDA where appropriate.
For security reviews, contact support@speculafree.com
FAQ
Security FAQ
Security review
Need to review SpeculaFree for your organisation?
We can provide additional security, privacy, and compliance information for qualified business reviews. Request our security documents or contact us for enterprise due diligence.
SpeculaFree is not built around ordinary document storage. It is built around protected document workflows: encryption, controlled access, signing evidence, final artifact protection, and audit-ready activity records.