Skip to content
Ravisign
DocumentationSecurity

Privacy and security

This page summarizes how Ravisign handles the data of your account and your signers, and what you can do to keep the integration secure. The complete rules are in the Terms of use and the Privacy policy, in the website footer.

Data processed#

Group Data
Account and users Legal name, CNPJ, name, email address, phone number, language, access credentials, access logs and logs of administrative actions
Signers Name, email address, phone number, CPF or CNPJ when provided, signature mark and the signature evidence: date and time, IP, device and browser, code channel and, with consent, the device location. Selfie and document photo only when the account requires them (feature coming soon)
Documents The original PDF, the final copy and the SHA-256 digests of each one
Visitors to the website and the validator IP and technical access data. The PDF uploaded to the validator is processed on the spot and is not stored

Roles under the LGPD#

  • Your company is the controller of the signers' data and of the content of the documents: it decides what to send and to whom.
  • Ravi Systems is the processor of this data: it processes it only to provide the signature service, according to your company's instructions.
  • For the registration data of the account, of the panel users and of website visitors, Ravi Systems is the controller.

Requests from data subjects about the data in a document should first be addressed to the company that sent the document; Ravi Systems cooperates so that the company can fulfill them.

Data protection#

  • HTTPS only: all traffic, from the panel, the signing page, the validator and the API, is encrypted.
  • Data in Brazil, on Ravi Systems servers. Ravisign is not installed on customer servers.
  • A dedicated key per account: each account has its own encryption key. It is used to encrypt sensitive data, such as the signers' CPF and CNPJ, the webhook secrets and the confirmation codes delivered through the conversation. The data of one account is never opened with the key of another.
  • Passwords are stored only as an irreversible digest. So are API keys: Ravisign cannot show a key again after it is created.
  • Isolation between accounts: everything is always filtered by account. Through the API, an envelope from another account responds as if it did not exist.
  • Isolated platform certificate: the ICP-Brasil certificate that signs the final copies is kept separate from the rest of the system and is used only by the signing service.
  • Minimum exposure: the API and the webhooks return masked email addresses and phone numbers and never return CPF, IP or browser. The public validator shows only masked data and the hashes.
  • Restricted and logged administrative access, encrypted backups.

The platform and the certificate#

The final copy of each envelope is signed in PAdES with the platform certificate, an ICP-Brasil e-CNPJ belonging to Ravi Systems, and receives a timestamp from an ICP-Brasil authority. The timestamp authority receives only cryptographic digests, never the document. See Final copy and manifest.

Retention and deletion#

Data How long
Selfie and document photo Deleted automatically 90 days after the envelope is completed, or within the period configured by the account in Settings
Documents, signer data and trail While the account is active and, afterwards, for the retention period, to allow the parties to defend their rights
Canceled account Documents and personal data of the signers are securely deleted after the retention period (default 365 days)
Audit trail Remains, since it does not contain name, email address, phone number, CPF, selfie or document, and is necessary for the integrity of the chain of all documents on the platform

Automatic deletion runs periodically, without manual intervention.

Best practices for API keys#

  • Keep the key on the server only, in a secrets vault or in an environment variable. Never in code that runs in the browser or in the customer's app, and never in a code repository.
  • Create one key per integration, with a clear name and only the scopes needed. A system that only queries does not need envelopes.escrever.
  • Revoke immediately any key that may have leaked (for example, sent by mistake in a message) and create another one. Revocation takes effect immediately.
  • Rotate keys periodically and whenever someone with access to them leaves the team.
  • Do not log the full key.

Best practices for webhooks#

  • Use a public HTTPS address without redirects.
  • Always verify the signature X-Ravisign-Assinatura with the webhook secret, calculating the HMAC over the raw body and comparing in constant time. Reject anything that does not match. The PHP example is in Webhooks.
  • Ignore repeats using the X-Ravisign-Entrega header, which is the same in all attempts of the same delivery.
  • Store the webhook secret encrypted, like a password.
  • Respond 2xx quickly and process afterwards. If in doubt about the order of events, confirm the status with envelopes/detalhe.
  • The confirmation code that arrives in signatario.otp_solicitado must be delivered and discarded: do not store or log it.

Best practices for the team#

  • Turn on two-step verification, especially for owners and administrators.
  • Give each person the most limited role that covers their work, and deactivate users who leave the company.
  • Turn on selfie and document photo only when they are truly necessary: this data may be considered biometric.
  • Keep track of the account audit log in Settings.

Data protection officer#

The Ravi Systems officer in charge of personal data processing can be reached at contato@ravisystems.com.br. Use this channel to exercise your rights, ask questions or report an incident.

Did not find what you were looking for?

Contact Ravi Systems support at the e-mail below.

contato@ravisystems.com.br