Trust
Security
Last updated: August 2026
Your documents are often your most sensitive records. This page explains how Dastkhat protects them — in transit, at rest, and after they are signed.
Encryption
All traffic to and from Dastkhat is encrypted in transit using TLS. Documents and account data are encrypted at rest by our hosting providers. Passwords are never stored in plain text — they are hashed.
Hosting and access control
Data is hosted with reputable cloud providers in the European Union, under their physical and network security controls. Internally, access to your documents is restricted on a need-to-know basis, protected by authentication, and logged. A Pakistan-based data centre is on our roadmap.
Document integrity and audit trail
When a document is completed, it is sealed so that any later change is detectable — the signed file is tamper-evident. Each document carries an audit trail recording who signed, when, and from where. Anyone can confirm a signed document is genuine and unaltered with our free validator.
Authentication
Accounts are protected by password authentication, and signer identity is verified by email before a signature is captured. We continue to invest in stronger authentication options.
Availability and backups
We rely on resilient cloud infrastructure and take regular backups so that your documents remain available and recoverable. No service can promise perfect uptime, but we design for reliability and monitor for problems.
Reporting a vulnerability
If you believe you have found a security vulnerability in Dastkhat, please tell us before disclosing it publicly. Email support@dastkhat.pk with the details and steps to reproduce, and we will investigate promptly. We appreciate responsible disclosure.