Encryption
Every form is served over HTTPS with TLS 1.2+ in transit. Submissions, attachments and generated PDFs are encrypted at rest using AES-256 on our storage provider.
Hosting & availability
Forms run on enterprise cloud infrastructure with automatic failover and uptime monitoring. We monitor availability continuously and are alerted the moment a form link stops responding.
Backups & recovery
Submission data and form configurations are backed up daily with point-in-time recovery. Backups are encrypted and retained for 30 days.
Audit trails
Every submission is timestamped and records the completion time, device type, IP address and signature event — giving you a defensible record of what was signed and when.
Electronic signatures
Signatures are captured with consent wording and a tamper-evident audit record, in line with the Electronic Communications and Transactions Act (ECTA) requirements for ordinary electronic signatures.
Access control
Submissions are delivered only to the addresses you nominate. Administrative access is limited to named StellorApp personnel, protected with multi-factor authentication.
POPIA alignment
We process personal information strictly on your instruction as operator. Forms include consent wording, purpose statements and lawful-basis language, and we support data subject access and deletion requests.
Retention & deletion
Retention periods are set per plan (12–36 months) and can be tailored. On request or on cancellation, we permanently delete your submission data and confirm deletion in writing.
Reporting a security concern
If you believe you have found a vulnerability or a data-handling issue, email martin@stellorapp.com with the details. We acknowledge all reports within one working day and will keep you updated until the matter is resolved.
