Security & trust

When we say "encrypted, tamper-evident records," "ESIGN & UETA-aligned e-signatures," or a "court-grade audit trail," this page is what we mean: how SubLien produces, stores, and proves electronic signatures, and the evidence available to parties, their counsel, and courts if a signature is contested.

Trust Services Statement · Version 2026-07-v1 · Effective July 19, 2026

Download the signed statement as PDF (2026-07-v1)

What SubLien is

SubLien provides software-as-a-service that facilitates the creation, delivery, electronic signature, and retention of construction lien waiver workflow documents and related vendor compliance records — certificates of insurance (COI) and W-9 collection status — for United States general contractors and their subcontractors.

Legal framework

SubLien's electronic signature service is designed to support compliance with the federal Electronic Signatures in Global and National Commerce Act (ESIGN Act, 15 U.S.C. 7001 et seq.) and the Uniform Electronic Transactions Act (UETA) as adopted by each U.S. state. State-specific lien waiver templates or workflows may be used where configured (Arizona, California, Florida, Georgia, Massachusetts, Michigan, Mississippi, Missouri, Nevada, Texas, Utah, Wyoming and others). SubLien is not a law firm and does not guarantee legal validity or enforceability. Enforceability can still depend on customer legal review, the correct statutory form, payment facts, signer authority, notarization requirements, and project-specific facts.

Signer authentication

Before signing, each signer completes an email-delivered One-Time Password (OTP) challenge. The six-digit code is hashed with a salted SHA-256, stored, and expires after 10 minutes. Upon successful verification, a cryptographically random session token (32 bytes, 256 bits of entropy) binds the authenticated session to the signing action. Failed attempts are rate-limited and locked after five consecutive failures.

Consent to electronic records

Prior to signing, each signer must affirmatively accept a Consumer Disclosure that describes the ESIGN Act, their right to receive a paper copy, their right to withdraw consent, the hardware and software requirements, and the data that will be captured. The exact text of the Consumer Disclosure is hashed (SHA-256) and stored alongside the signed record, so the precise version of the disclosure accepted by the signer can be proven in a dispute.

Evidence captured at signing

For each electronic signature SubLien records: UTC timestamp, IP address, parsed user agent (browser, operating system, device type), geolocation derived from request metadata where available, authentication method, signer name and title, signer authority certification, Consumer Disclosure version and hash, viewport, timezone, and language values supplied by the browser, and a cryptographic hash of the frozen document content. When the browser supplies a signing-page DOM snapshot and private object storage accepts it, that snapshot is stored as supplemental evidence.

Document integrity

Each rendered waiver is hashed with SHA-256 at the time of sending. The same hash is recomputed at the time of signing and compared; any mismatch aborts the signature. A second SHA-256 hash is computed over the signing payload (document hash + signer identity + signer authority certification + timestamp + IP + disclosure hash) and stored as the Signature Hash. The signing payload is retained in audit metadata so the Signature Hash can be recomputed from the evidence export.

Audit trail and retention

Document lifecycle events are appended to an immutable audit log: Created, Sent, Viewed, OTP Sent, OTP Verified, Consent Accepted, Signed, email delivery events, Reminder Sent, Revoked, Expired. Events written through the audit service store their own IP, user agent, browser, OS, device type, geolocation, previous-entry hash, and entry hash. The CSV evidence export includes these hash-chain fields and a verification result. Signed PDFs, certificates, audit logs, and available supplemental evidence are retained for a minimum of ten (10) years and produced on request in response to valid legal demands.

PDF sealing and trusted timestamps

SubLien may attach supplemental RFC 3161 timestamp tokens and embedded PDF signatures when the corresponding services and signing certificate are configured and complete successfully. These controls are additional integrity evidence. SubLien does not represent that a self-signed PDF certificate provides the same third-party identity assurance or court familiarity as a DocuSign-style AATL-backed seal.

Infrastructure and storage

SubLien runs on Vercel (SOC 2 Type II) with serverless compute in the United States. Application data is stored in Neon Postgres (SOC 2 Type II). Signed PDFs, DOM snapshots, and other evidence are stored as private objects in Vercel Blob Storage, encrypted at rest. All traffic is protected with TLS 1.2 or higher.

What we produce in a dispute

Upon receipt of a formal dispute, subpoena, or legal hold notice, SubLien can provide, for any envelope where available: the signed PDF with its embedded Certificate of Completion; the complete audit trail as a structured CSV export with hash-chain fields and verification result; the frozen waiver HTML and document hash; the signing payload used to compute the Signature Hash; the Consumer Disclosure text and hash that were accepted; available DOM snapshot and timestamp evidence; and a copy of the Trust Services Statement. Requests are fulfilled within five (5) business days where feasible.

Templates and customer legal review

SubLien-provided waiver templates are workflow aids only. Before an organization may send a waiver using a SubLien-provided system template, it must attest that its legal counsel reviewed and approved the specific state, waiver type, and template hash for that organization's use. Customer-uploaded waiver templates are the customer's responsibility, including legal review, permitted jurisdictions, field placement, and allowed use cases.

Verify any document yourself

You don't have to take our word for any of this. Anyone holding a signed waiver's document hash or Signature Hash can check it against SubLien's records — no account required.

Verify a document →

Contact

Questions about this statement: compliance@sublien.com