Skip to content
Notificado

Security

The evidence does not depend on trusting us

We built Notificado so an expert witness can verify every notification without our system, ten years from now. This is how we handle data and how we protect it.

Glass blocks linked by rings, one after another: a hash chain as an object.

Personal data (Ley 1581 de 2012)

For the recipient's data, the lawyer or firm is the data controller (responsable) and Notificado is the processor (encargado): we process it on their behalf, only to serve the notification and prove it. For your account data, we are the controller.

  • The processing relationship is governed by the data transfer agreement that is part of the terms of service.
  • The verification page never shows the message content or any personal data of the recipient.
  • Every data subject can access, update, correct and delete their data on the terms of our policy.
Data processing policy

Immutable storage for 10 years

Frozen messages, documents, timestamps, constancias and the providers' original responses are kept in Amazon S3 with Object Lock in compliance mode for ten years. During that time no one can delete or overwrite them, not even a Notificado administrator.

  • Encryption in transit (TLS) on every connection, and at rest in evidence storage.
  • An insert-only event log: the database refuses any update or deletion.
  • A nightly check of the whole chain and a daily anchor, timestamped.

Restricted, audited access

Each firm sees only its own cases and notifications. When our team looks at a customer's data, the read is logged with who, when and what; every evidence download is logged as an event too.

  • Least-privilege roles for our own team: operations, support, finance and compliance.
  • API tokens are stored only as a hash, shown once and revocable at any time.
  • An AI assistant never sends on its own: a person confirms every send.

Vendors behind interfaces

Mail, timestamping and constancia signing go through our own interfaces, not a vendor's format. The evidence uses open standards (RFC 3161 for timestamps, PAdES for the signature, SHA-256 and RFC 8785 for fingerprints), so it stays verifiable even if we change vendors.

Read the evidence method

If an incident happens

If a security incident affects personal data, we inform the affected customers, who are the data controllers, and Colombia's Superintendencia de Industria y Comercio, as Ley 1581 requires.

Privacy policy

Report a vulnerability

If you find a security flaw, write to us with the steps to reproduce it. We ask that you do not access other people's data, do not degrade the service, and give us reasonable time to fix it before you publish.

Write to admin@notificado.co

Verify it yourself

The evidence method is public and versioned, and any constancia can be checked on the verification page.