Security note · v1.1 · October 2026

No document content ever leaves your device.

This note is for your IT and security reviewers. It describes how Under Seal processes documents, the one network channel it uses, exactly what that channel carries, and how to verify each claim yourself.

Architecture

default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self';
img-src 'self' data: blob:; connect-src 'self' https://underseal-activation-production.up.railway.app;
worker-src 'self' blob:; object-src 'none'; base-uri 'none'; form-action 'none'; frame-src 'none'

Exactly what Under Seal sends

There are three requests, all POST with a JSON body to https://underseal-activation-production.up.railway.app. These are all of the fields:

RequestFieldsWhen
/v1/activateactivation_code · install_id (random UUID created on the device) · app_version · label (optional, ≤ 60 characters, e.g. "Tax room 2")Once per computer
/v1/checkinlicence_id · install_id · app_version · period_key · docs (documents this computer processed this period)At start-up, every 6 hours, when the computer's share of the allowance is used, and on reconnect
/v1/releaselicence_id · install_idWhen a seat is freed

A complete check-in body, exactly as sent:

{ "licence_id": "lic_3f9a0c41d2e87b65", "install_id": "6f1c2a3b-4d5e-4f60-8a7b-9c0d1e2f3a4b",
  "app_version": "1.3.0", "period_key": "M2027-04", "docs": 37 }

Never sent: document content, file names, file sizes, file hashes or fingerprints, detected values, findings, document metadata, user names, e-mail addresses, and device or hardware identifiers. The installation ID is random and not derived from the hardware. Without activation, the app processes samples only and makes no network requests at all.

What the service stores: the licence (tier, term, allowance, paid-through date, a SHA-256 hash of the activation code), installations (random ID, optional label, activation and last check-in times), per-period document counts, an audit log of licence events, and for billing only the Stripe customer and subscription IDs plus each billing event's ID, type and outcome (never card or bank details). It does not log IP addresses, user agents or request bodies; it logs method, path and status only. The hosting provider's edge infrastructure may process connection metadata.

What the service returns

A lease: a JSON payload signed with ECDSA P-256 / SHA-256 (ES256). The app verifies it against a public key pinned in the app, which is also published at /v1/public-key. The lease states the tier, the allowance period (in Eastern time), the pooled allowance and usage across the firm, this computer's share (quota), seats in use, the paid-through date, and when it expires.

Time, entitlement and offline behaviour

SituationWhat the app does
OnlineChecks in at start-up and every 6 hours; the lease renews each time.
Offline, within the graceWorks normally, up to this computer's share of the remaining allowance. Grace is 7 days on monthly terms and 14 on annual terms.
Offline, share usedPauses new documents on this computer until it checks in.
Offline beyond the gracePauses new documents until it can renew.
Device clock wound backPauses until one check-in confirms the time. Moving the clock back cannot extend the grace.
Allowance period ended while offlinePauses until a check-in opens the new period; the old period's count is reported first.
Licence revoked, suspended or lapsedTakes effect at the next check-in (within 6 hours online).
Computer unused for 30 daysIts seat is freed; it rejoins automatically at its next check-in if a seat is available.

Cryptography

How to verify

Limits, stated plainly

Questions from your security team: support@underseal.app.