Skip to content
Canadian owned and hosted. Your documents stay in Canada.
Security

The page to hand your security reviewer

Everything below is also somewhere else on this site or in our agreements. It is collected here because a questionnaire is answered in one sitting, not by reading a website.

Where it runs

On hardware Nimble owns and operates. There is no hyperscaler underneath, and no customer-hosted or bring-your-own-cloud option exists.

Canadian facilities

Protected B certified facilities in Aurora, Ottawa and Winnipeg, staffed by security-cleared Canadian personnel. Your documents are stored, processed and backed up inside them.

Canadian jurisdiction

Nimble is Canadian-owned with no foreign parent, so no foreign court or statute, the US CLOUD Act included, has a route to compel the company operating the servers.

Audited operation

Nimble is SOC 2 Type II audited, aligns its infrastructure to ITSG-33, and is compliant with PIPEDA, PHIPA, FIPPA and ITSP.10.033.

Encryption

In transit and at rest, with the at-rest half doing more than the phrase usually means.

In transit
Everything between a browser and NimbleSign travels over TLS, including the links signers open and the webhook callbacks your systems receive.
At rest
Documents and signature images are encrypted with AES-256-GCM under a key held by the deployment, each with its own random nonce. GCM authenticates as well as encrypts, so a tampered or wrongly-keyed blob fails loudly rather than decrypting to something plausible.
Keys can be rotated without a migration
Every stored object records the key it was written under, so a rotation retires the old key rather than re-encrypting the estate, and which objects still ride it is a query rather than a filesystem crawl.
Stored credentials too
Settings marked secret, such as an SMTP password or an API credential, are encrypted under the same key and are never readable back out of the console that sets them.

Who can see what

Three roles, and an organization boundary that no query crosses.

The roles

An Admin manages accounts and sees the whole organization. A Sender sends envelopes and sees only their own. A Viewer reads the organization and changes nothing.

Checked three times

A request is authorized at the page, again in the service behind it, and a third time in the query, which is scoped to the caller’s organization before it runs. The REST API goes through the same services, so it is scoped identically.

Proven, not asserted

A test suite exists purely to fail if one organization can read or write another’s data, at every layer. It runs on every build.

Getting in

Your staff sign in. Your signers never do.

Passwords
Twelve characters minimum, with no character-class rule and no forced rotation, because both push people toward a predictable password and a sticky note. What is refused instead is the shapes people use to reach twelve: a common word padded with digits, one character repeated, a run along the keyboard, or the account’s own name or email.
Two-step verification
Standard authenticator-app codes with single-use recovery codes. An organization can require it of every member, in which case an unenrolled account enrols before the sign-in completes rather than after.
Or your own identity provider
Single sign-on against the directory you already run, so joiners and leavers are handled where you already handle them and there is no second password to manage.
Sessions end when you say so
Deactivating an account or changing its password invalidates its existing sessions, so access stops at the moment you revoke it rather than whenever a cookie happens to expire.
Signers create no account
A signer opens a single-use link and confirms a code. There is no password to reuse, no account to breach, and nothing for them to install.

What gets recorded

Every step of an envelope, in an order that cannot be quietly edited afterwards.

A chain, not a log

Each event is hash-chained to the one before it. Removing or altering an entry breaks the chain, and the break is detectable by anyone holding the finished envelope.

Sealed on completion

A finished envelope carries a digital seal over the documents and the certificate together, with a trusted timestamp where one is configured.

And it verifies

The certificate states pass or fail against that chain, so an alteration after the fact does not merely look suspicious, it fails a check anyone can run.

If something goes wrong

No system is perfectly secure, and a page that implies otherwise is not worth reading. If a breach of our safeguards creates a real risk of significant harm, we notify the affected individuals and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and the affected customers without undue delay.

Nimble’s Privacy Officer is accountable for this, and is also the person in charge of protecting personal information for the purposes of Quebec law.

The commitment in full, in the Privacy Policy

And if you leave

For 30 days after an account closes you can export your completed envelopes and their certificates in ordinary formats. Content is then deleted from active systems on our retention schedule, with backups ageing out on a defined cycle.

Anything already downloaded keeps working. A sealed document verifies on its own, without us and without an account.

What we don’t claim

A reviewer who finds a gap we skipped past trusts nothing else on the page, so here are ours.

NimbleSign holds no certification of its own
Protected B, SOC 2 Type II and ITSG-33 describe Nimble and the infrastructure NimbleSign runs on. They are not product certifications, and we would rather say so than let a badge imply one.
It is not a secure electronic signature
A NimbleSign signature is a valid electronic signature under PIPEDA, ESIGN and UETA. A small number of federal uses call for a “secure electronic signature”, a narrower standard built on certificates from a government-recognised authority. That is a different thing, and this is not it.
No accessibility standard is claimed
We describe what the product actually does rather than name a standard we have not been audited against.
No uptime figure is published
There is no service level commitment on this page because none has been set. If your review needs one, ask, and you will get an answer rather than a number written for a website.

Still have a questionnaire to fill in?

Send it to us. We would rather answer it than have you guess from a website, and the answers come from the people who run the thing.

Where this comes from: the Privacy Policy governs personal information and the Terms of Use govern the service. Where this page and either of those differ, the agreement wins.