Security and trust

Make the agreement boundary fail closed.

TermsForward is designed around tenant isolation, least privilege, exact evidence, explicit human authority, and reconciliation when an external effect is uncertain.

Design principles

Controls that reflect the agreement's real stakes.

Isolation

Scope every read and write.

Tenant and legal-entity context is intended to be explicit, database-enforced, and unavailable when the requested scope does not match.

Evidence

Preserve exact bytes and transitions.

Immutable object versions, document hashes, database constraints, and append-only audit evidence help show what changed and when.

Authority

Do not infer a human decision.

Approval, dispatch, and signature are separate capabilities. AI can assist review, but cannot accept terms or create authority.

Private signing routes

Native signing sessions are designed to be agreement-specific, version-bound, expiring, single-use, non-cacheable, non-indexable, and resistant to referrer leakage.

Provider neutrality

External signature and delivery systems can be adapters. Authenticated callbacks and provider responses must be reconciled before they can drive authoritative agreement state.

Immutable storage

The production candidate uses versioned Object-Locked storage for retained evidence. Complete object-version disaster recovery and accepted recovery objectives remain open gates.

Current posture

TermsForward is a governed private-pilot product. High availability, formal compliance certification, and a public security assurance package are not yet claimed.

Security evaluation

Bring the controls your agreement workflow requires.

Contact security