Security at Capy Tools
We design CapySign and the shared Capy platform to protect private files, signing links, accounts, transactions, and audit evidence.
Core safeguards
- Encrypted HTTPS connections.
- Private object storage and server-side authorization checks.
- Cryptographically random recipient tokens stored as hashes.
- Document integrity checks using SHA‑256 hashes.
- Structured signing and transaction audit records.
- Ledger-based, idempotent credit and purchase operations.
- Origin checks plus upload type, size, and request validation.
- Signed payment webhooks and entitlement-gated plugin downloads.
Signing-link limitations
Anyone possessing a signing link can act as its recipient. Links expire after 30 days and the sender can rotate or revoke them. A link and a typed or drawn signature do not independently verify someone’s identity. Invitation emails and reminders are not automated in this release.
Your responsibilities
Protect your ChatGPT account and email with multifactor authentication, verify recipient addresses, share signing links only through trusted channels, keep independent copies of important records, and promptly void a request if a link or account may be compromised.
Responsible disclosure
If you believe you found a vulnerability, email security@capytools.com with reproduction steps and potential impact. Do not access data that is not yours, disrupt service, use social engineering, or publicly disclose an issue before we have had a reasonable opportunity to investigate. Good-faith research consistent with this policy will be considered authorized to the extent we can lawfully provide that assurance.
Incident response
We investigate suspected incidents, contain risk, preserve relevant evidence, remediate vulnerabilities, and provide legally required notices to affected customers or authorities.
No absolute guarantee
No online system is completely secure. Our security page describes practices and goals, not a warranty or certification.
Questions? Contact legal@capytools.com.