EverStamp EverStamp

BeveiligingSecurity

Hoe EverStamp bewijs en gegevens beschermt, waar wat staat, en eerlijk wat er nog niet is. Geschreven voor wie een leverancier beoordeelt.How EverStamp protects evidence and data, where everything is held, and an honest account of what is not there yet. Written for the person assessing a supplier.

Stand 30 september 2026. Deze pagina wordt bijgewerkt bij elke wijziging in de opzet; de datum zegt hoe vers hij is.As at 30 September 2026. This page is updated whenever the setup changes; the date tells you how fresh it is.

In één oogopslagAt a glance

OnderwerpStandToelichting
TopicStatusNotes
Controle zonder vertrouwen in EverStampjaElke foto en elk dossier is te controleren met open standaarden (C2PA, RFC 3161, de Europese vertrouwenslijst); elke controle behalve die tegen ons register werkt ook als EverStamp niet meer bestaat.
Verification without trusting EverStampyesEvery photo and every file can be checked with open standards (C2PA, RFC 3161, the European trust list); every check except the one against our registry also works if EverStamp no longer exists.
Foto's op onze serversnee, tenzij u deelt, een verzoek beantwoordt of uw organisatie bewaren aanzetFoto's blijven op het toestel. Een deellink zet een versleuteld archief tijdelijk bij ons, met een sleutel die alleen in de link zit. Een levering (het antwoord op een verzoek) en bewaren bij EverStamp (een keuze van de organisatie, voor al haar dossiers) zetten het archief bij ons met de sleutel versleuteld in de kluis van het register. Omdat wij de sleutel beheren, kan EverStamp het technisch openen; dat doen wij alleen op schriftelijk verzoek van de organisatie, of als een bevoegde rechter of autoriteit ons daartoe met een bevel of vordering op grond van de wet verplicht. Zo’n bevel of vordering toetsen wij, wij verstrekken niet meer dan gevorderd, en wij melden het de organisatie vooraf of zo snel als dat mag, tenzij de wet die melding verbiedt. Via het dashboard of de API openen alleen een eigenaar, beheerder of API-sleutel van de organisatie het, en elke opening via het dashboard of de API staat in haar logboek.
Photos on our serversno, unless you share a file, answer a request, or your organisation turns on storage at EverStampPhotos stay on the device. A share link places an encrypted archive with us temporarily, under a key that sits only in the link. A delivery (the answer to a request) and storage at EverStamp (a choice of the organisation, for all its files) place the archive with us with the key encrypted in the vault of the registry. Because we manage the key, EverStamp can technically open it; we do so only at the organisation’s written request, or if a competent court or authority obliges us to by an order or demand based on the law. We review such an order or demand, we provide no more than is demanded, and we tell the organisation in advance or as soon as that is allowed, unless the law forbids that notice. Through the dashboard or the API only an owner, administrator or API key of the organisation opens it, and every opening through the dashboard or the API is written to its audit log.
Versleuteling onderweg en in rustonderweg ja, in rust deelsTLS met HSTS. Archieven (deellinks, leveringen, bewaarde dossiers) zijn met AES-256-GCM versleuteld, en de geheimen in de database ook. De database van het register zelf, met onder meer namen, checklists en veldwaarden, staat niet versleuteld op de schijf van de server, net als de recente back-ups daar; de kopieën buiten de server zijn versleuteld met een sleutel die niet op de server staat.
Encryption in transit and at restin transit yes, at rest partlyTLS with HSTS. Archives (share links, deliveries, kept files) are encrypted with AES-256-GCM, and so are the secrets in the database. The registry database itself, with among other things names, checklists and field values, is not encrypted on the server’s disk, nor are the recent backups there; the copies off the server are encrypted with a key that is not on the server.
Signeersleutel in een HSMjaAWS KMS (Frankfurt); de sleutel verlaat de HSM nooit.
Signing key in an HSMyesAWS KMS (Frankfurt); the key never leaves the HSM.
Toestellen aantoonbaar echtjaApple App Attest (iPhone) of Android Key Attestation bij elke registratie: alleen een ongewijzigde EverStamp-app op een echt toestel komt binnen.
Devices demonstrably genuineyesApple App Attest (iPhone) or Android Key Attestation on every registration: only an unmodified EverStamp app on a real device gets in.
Auditlog van handelingenjaElke handeling op het dashboard en via de API, met wie en wanneer; plus een openbaar, gestempeld logboek.
Audit log of actionsyesEvery action in the dashboard and through the API, with who and when; plus a public, timestamped log.
Monitoring en statuspaginajaEen wachter op de server die elke vijf minuten kijkt, en een onafhankelijke externe monitor; everstamp.app/status.
Monitoring and status pageyesA watcher on the server that checks every five minutes, and an independent external monitor; everstamp.app/status.
Back-ups en hersteljaElk uur, op drie plekken bij twee leveranciers: op de server, en daarbuiten versleuteld bij Cloudflare R2 en in een Storage Box van Hetzner, met een sleutel die niet op de server staat; ontbreekt er op een van de drie een kopie langer dan drie uur, dan slaat de wachter alarm; herstel van het register volgens een runbook.
Backups and recoveryyesEvery hour, in three places with two providers: on the server, and off the server encrypted at Cloudflare R2 and in a Hetzner Storage Box, with a key that is not on the server; if a copy is missing in any of the three for more than three hours, the watcher raises an alarm; recovery of the registry according to a runbook.
Gegevens in de EUjaServers in Duitsland; opslag en database in EU-regio's. De lijst van subverwerkers staat onderaan.
Data in the EUyesServers in Germany; storage and database in EU regions. The list of subprocessors is at the bottom.
Verwijderen op verzoekjaEen organisatie kan zichzelf opheffen: alles wordt gewist of ontdaan van namen en contactgegevens, tot in het register. De koppelingen van telefoons worden ingetrokken in plaats van gewist, zodat de app een keer kan melden dat hij is ontkoppeld; de naam van de organisatie blijft daardoor nog veertien dagen in die ingetrokken koppeling, alleen zichtbaar voor dat toestel.
Deletion on requestyesAn organisation can close itself down: everything is erased or stripped of names and contact details, right into the registry. The links of phones are revoked rather than deleted, so that the app can report once that it has been unlinked; the organisation’s name therefore stays in that revoked link for another fourteen days, visible only to that device.
Export van alle gegevensjaEen zip met alles van de organisatie, als json en csv, door een beheerder zelf te maken.
Export of all datayesA zip with everything belonging to the organisation, as JSON and CSV, generated by an administrator.
MFA voor uw gebruikersjaInloggen gaat zonder wachtwoord, via een link naar het e-mailadres of met Google of Microsoft, met een tweede stap via een app met codes (TOTP) voor wie die instelt. De eigenaar kan de tweede stap verplicht maken voor beheerders of voor iedereen; de database dwingt dat af, ook voor wie de database rechtstreeks aanspreekt. De eis zit op het aanvaarden van een uitnodiging en op de gegevens van de organisatie, niet op het zien van de uitnodiging zelf.
MFA for your usersyesSign-in is passwordless, through a link sent to the email address or with Google or Microsoft, with a second step through an authenticator app (TOTP) for anyone who sets it up. The owner can make the second step mandatory for administrators or for everyone; the database enforces it, also for anyone who calls the database directly. The requirement sits on accepting an invitation and on the data of the organisation, not on seeing the invitation itself.
SSO en SCIMnog nietOp de roadmap voor Enterprise.
SSO and SCIMnot yetOn the roadmap for Enterprise.
ISO 27001, SOC 2nog nietGeen certificering; deze pagina en de open verificatie zijn wat we nu kunnen laten zien.
ISO 27001, SOC 2not yetNo certification; this page and the open verification are what we can show you today.

Het ontwerp: bewijs dat u zelf kunt nagaanThe design: evidence you can check yourself

EverStamp is gebouwd op één uitgangspunt: het bewijs mag niet rusten op vertrouwen in EverStamp. Daarom ontstaat het bewijs op het toestel, met open standaarden, en kan iedereen het verifiëren.

EverStamp is built on a single principle: the evidence must not rest on trusting EverStamp. So it is created on the device, with open standards, and anyone can check the sums.

Wat wij niet zien. Foto's, notities en posities blijven op het toestel. Het register bewaart per dossier een hash, een volgnummer en de wortel, en bij een dossier van een organisatie of een verzoek ook de naam van het dossier, de checklist, de veldwaarden en de naam van het lid of de gast; nooit beelden. Alleen een deellink, een levering of bewaren bij EverStamp zet een archief bij ons, versleuteld met AES-256-GCM. Bij een deellink zit de sleutel in de link en wordt hij nooit naar ons verstuurd; bij een levering en bij bewaren houdt het register hem versleuteld in zijn kluis voor de organisatie. Omdat wij de sleutel beheren, kan EverStamp zo'n archief technisch openen; dat doen wij alleen op schriftelijk verzoek van de organisatie, of als een bevoegde rechter of autoriteit ons daartoe met een bevel of vordering op grond van de wet verplicht. Zo’n bevel of vordering toetsen wij, wij verstrekken niet meer dan gevorderd, en wij melden het de organisatie vooraf of zo snel als dat mag, tenzij de wet die melding verbiedt. Elke opening via het dashboard of de API staat in het auditlog van de organisatie.

What we do not see. Photos, notes and positions stay on the device. Per file the registry holds a hash, a sequence number and the root, and for a file of an organisation or a request also the name of the file, the checklist, the field values and the name of the member or the guest; never images. Only a share link, a delivery or storage at EverStamp places an archive with us, encrypted with AES-256-GCM. With a share link the key sits in the link and is never sent to us; with a delivery and with storage the registry keeps it encrypted in its vault for the organisation. Because we manage the key, EverStamp can technically open such an archive; we do so only at the organisation’s written request, or if a competent court or authority obliges us to by an order or demand based on the law. We review such an order or demand, we provide no more than is demanded, and we tell the organisation in advance or as soon as that is allowed, unless the law forbids that notice. Every opening through the dashboard or the API is written to the organisation’s audit log.

Gegevens en waar ze staanData, and where it is held

WatWaarBewaartermijn
WhatWhereRetention
Het register (hashes, volgnummers, wortels, toestelkoppelingen)Eigen server bij Hetzner, Nürnberg (DE)Onbeperkt: het is de vertrouwensbasis. Persoonsnamen erin worden gewist bij opheffen; de naam van de organisatie blijft nog veertien dagen in de ingetrokken koppeling van een telefoon, alleen zichtbaar voor dat toestel.
The registry (hashes, sequence numbers, roots, device bindings)Our own server at Hetzner, Nuremberg (DE)Indefinite: it is the basis of trust. Personal names in it are erased on closure; the organisation’s name stays for another fourteen days in a phone’s revoked link, visible only to that device.
Organisaties, leden, opdrachten, verzoeken, auditlogRegister (Hetzner) en dashboarddatabase (Supabase, EU)Zolang de organisatie bestaat; bij opheffen gewist, behalve de naam van de organisatie in de ingetrokken koppeling van een telefoon, die na veertien dagen weggaat; contactgegevens van gasten dertig dagen na afloop
Organisations, members, jobs, requests, audit logRegistry (Hetzner) and dashboard database (Supabase, EU)For as long as the organisation exists; erased on closure, except the organisation’s name in a phone’s revoked link, which goes after fourteen days; guests’ contact details thirty days after the request ends
Gedeelde archieven, leveringen en bewaarde dossiersCloudflare R2, EU-jurisdictie, versleuteld; de sleutel van een levering of bewaring versleuteld in het register (Hetzner)Zolang de link geldig is: standaard 30 dagen bij Basis en 30 bij Plus en Business, hooguit 30, 90 of 365 dagen; leveringen en bewaarde dossiers zolang het abonnement loopt, of een kortere termijn die u zelf instelt. Bij verlopen of intrekken gaan bestand en sleutel weg; een versleutelde regel zonder bestand blijft hooguit 17 dagen in een back-up
Shared archives, deliveries and kept filesCloudflare R2, EU jurisdiction, encrypted; the key of a delivery or a kept file encrypted in the registry (Hetzner)For as long as the link is valid: 30 days by default on Basis and 30 on Plus and Business, at most 30, 90 or 365 days; deliveries and kept files for as long as the subscription runs, or a shorter period you set yourself. On expiry or withdrawal the file and the key are removed; an encrypted row without a file stays in a backup for 17 days at most
Back-ups van het registerOp de server zelf, en versleuteld met age in Cloudflare R2 en de Hetzner Storage BoxElke kopie is uiterlijk 17 dagen na het maken weg, op de server en versleuteld daarbuiten; het back-upscript rekent die grens zelf na, de kopieën van de hele server bij Hetzner meegeteld
Backups of the registryOn the server itself, and encrypted with age in Cloudflare R2 and the Hetzner Storage BoxEvery copy is gone at most 17 days after it was made, on the server and encrypted off the server; the backup script checks that limit itself, counting the copies of the whole server at Hetzner
Kopieën van de hele serverHetzner BackupsVolgens de instelling van ons abonnement daar (nu 7 dagen), meegeteld in de 17 dagen hierboven
Copies of the whole serverHetzner BackupsUnder the setting of our plan there (now 7 days), counted in the 17 days above
Back-ups van de dashboarddatabaseSupabase (EU)De back-ups maakt Supabase, volgens de instelling van ons abonnement daar (nu 7 dagen)
Backups of the dashboard databaseSupabase (EU)Supabase makes the backups, under the setting of our plan there (now 7 days)
Betalingen en facturenDashboarddatabase (Supabase, EU) en MollieTot zeven jaar na het einde van het jaar van de factuur, de fiscale bewaarplicht, ook na het opheffen van de organisatie
Payments and invoicesDashboard database (Supabase, EU) and MollieUntil seven years after the end of the year of the invoice, the statutory retention for tax records, also after the organisation is closed
KortingenDashboarddatabase (Supabase, EU); lezen alleen eigenaar en beheerder, schrijven alleen de dienstsleutel vanuit BeheerPercentage, einddatum, wanneer gezet en door welke beheerder van EverStamp, tot de korting wordt weggehaald of de organisatie opgeheven; op de factuur een eigen regel (‘Korting 50%’), met de termijn van de factuur; de reden in het beheerlog
DiscountsDashboard database (Supabase, EU); read by owner and administrator only, written only by the service key from BeheerPercentage, end date, when set and by which EverStamp administrator, until the discount is removed or the organisation is closed; on the invoice its own line (‘Discount 50%’), with the term of the invoice; the reason in the management log
SupportvragenDashboarddatabase (Supabase, EU); de mails via Resend en in onze mailbox bij Google WorkspaceTwee jaar nadat een vraag is gesloten gewist door de dagtaak; ook na het opheffen van de organisatie, dan zonder koppeling met de organisatie; de mails in onze mailbox bij Google Workspace zolang dat nodig is om de vraag af te handelen en op te volgen
Support questionsDashboard database (Supabase, EU); the emails through Resend and in our mailbox at Google WorkspaceDeleted by the daily job two years after a question is closed; also after the organisation is closed, then without the link to the organisation; the emails in our mailbox at Google Workspace for as long as needed to handle and follow up the question
Beheerlog (handelingen van de beheerder van EverStamp en mislukte betaalpogingen)Dashboarddatabase (Supabase, EU), alleen voor de beheerder12 maanden, daarna gewist door de dagtaak; tijd, account, handeling, onderwerp (ook een account) en details (zoals een foutmelding, de reden bij een creditnota, de reden en identiteitscheck bij een reset van de tweede stap, of de reden bij een korting met percentage en einddatum van voor en na), waarin bij uitzondering een naam kan staan
Management log (actions of the EverStamp administrator and failed payment attempts)Dashboard database (Supabase, EU), for the administrator only12 months, then deleted by the daily job; time, account, action, subject (also an account) and details (such as an error message, the reason for a credit note, the reason and identity check of a reset of the second step, or the reason for a discount with the percentage and end date before and after), which can exceptionally contain a name
Nieuws en productnieuws (wat een lid las, en de keuze voor productnieuws per e-mail)Dashboarddatabase (Supabase, EU)Zolang het account bestaat; bij verwijderen van het account gaan keuze, afmeldcode en leestijden mee. Geen e-mailadres; per melding alleen het tijdstip van mailen en het aantal ontvangers
News and product news (what a member read, and the choice for product news by email)Dashboard database (Supabase, EU)For as long as the account exists; when the account is deleted, the choice, the unsubscribe code and the read times go with it. No email address; per message only when it was mailed and the number of recipients
Cookies van het dashboardIn de browser, alleen op dashboard.everstamp.app, van het dashboard zelflang (taal), tz (tijdzone) en nav (menu open of ingeklapt) een jaar; de inlogcookies van Supabase: de sessie loopt af na 8 uur zonder activiteit en na hooguit 7 dagen (instellingen van ons Supabase-project), het cookie zelf blijft hooguit 400 dagen; de inlogpagina onthoudt in de browser (localStorage, geen cookie) het laatst gebruikte e-mailadres, alleen om het in te vullen als een link verlopen is; alleen functioneel, geen tracking. Vercel Web Analytics zet geen cookie, en everstamp.app zelf zet geen cookies
Cookies of the dashboardIn the browser, only on dashboard.everstamp.app, set by the dashboard itselflang (language), tz (time zone) and nav (menu open or collapsed) one year; the Supabase sign-in cookies: the session ends after 8 hours without activity and after 7 days at most (settings of our Supabase project), the cookie itself stays at most 400 days; the sign-in page keeps the last used email address in the browser (localStorage, not a cookie), only to fill it in when a link has expired; only functional, no tracking. Vercel Web Analytics sets no cookie, and everstamp.app itself sets no cookies
E-mail (inloggen, uitnodigingen, verzoeken, offerteaanvragen, contactberichten, betalingen, supportvragen, productnieuws, beveiliging)ResendEen inlog- of uitnodigingsmail: het adres en een link, bij een uitnodiging ook de naam van de organisatie. Een verzoekmail aan een gast: de naam van de organisatie, de titel, de einddatum, de notitie van kantoor en de link, geen dossierinhoud. Een offerteaanvraag: de naam, het e-mailadres, de organisatie en het bericht die de aanvrager invult. Een bericht via het contactformulier van de site: de naam, het e-mailadres, de organisatie als die is ingevuld, het onderwerp en het bericht. Een betaalmail aan elke eigenaar: het bedrag en waarvoor; bij een betaling of creditnota ook het nummer, met de factuur of creditnota als pdf-bijlage; na een mislukte incasso zonder bijlage. Een herinnering aan elke eigenaar, een keer, 30 dagen voordat een korting of gratis periode afloopt: de naam van de organisatie, het percentage en de einddatum; niet aan de mailbox voor facturen. Heeft de eigenaar een mailbox voor facturen opgegeven, dan krijgt die alleen de factuur of creditnota als pdf, in een neutrale mail zonder link. Een supportvraag: aan support@ de naam, het e-mailadres en de organisatie van wie de vraag stelt, het onderwerp en het bericht; aan de klant een bevestiging met het nummer en het onderwerp van de vraag, en elk antwoord van EverStamp. Een reset van de tweede stap: aan het lid een melding met een link om opnieuw in te loggen. Productnieuws, alleen aan leden die het zelf aanzetten: het e-mailadres, het onderwerp, de tekst in de taal van het account en een afmeldlink met een persoonlijke code, ook in de koppen List-Unsubscribe en List-Unsubscribe-Post. EverStamp bewaart geen kopie van de verstuurde mail, behalve wat in onze mailbox bij Google Workspace binnenkomt (offerteaanvragen, contactberichten en supportvragen): dat bewaren wij zolang dat nodig is om de vraag af te handelen en op te volgen; wat Resend bewaart staat bij de subverwerkers.
Email (sign-in, invitations, requests, quote requests, contact messages, payments, support questions, product news, security)ResendA sign-in or invitation email: the address and a link, for an invitation also the organisation’s name. A request email to a guest: the organisation’s name, the title, the end date, the office’s note and the link, no file content. A quote request: the name, email address, organisation and message the requester enters. A message through the site’s contact form: the name, the email address, the organisation if given, the subject and the message. A payment email to each owner: the amount and what it is for; for a payment or credit note also the number, with the invoice or credit note as a PDF attachment; after a failed direct debit without an attachment. A reminder to each owner, once, 30 days before a discount or free period ends: the organisation’s name, the percentage and the end date; not to the mailbox for invoices. If the owner set a mailbox for invoices, it gets only the invoice or credit note as a PDF, in a plain email without a link. A support question: to support@ the name, email address and organisation of the person asking, the subject and the message; to the customer a confirmation with the number and subject of the question, and each answer from EverStamp. A reset of the second step: to the member a notice with a link to sign in again. Product news, only to members who switched it on: the email address, the subject, the text in the language of the account and an unsubscribe link with a personal code, also in the List-Unsubscribe and List-Unsubscribe-Post headers. EverStamp keeps no copy of the email it sends, except what arrives in our mailbox at Google Workspace (quote requests, contact messages and support questions): we keep that for as long as needed to handle and follow up the question; what Resend keeps is listed with the subprocessors.
Toegangslog, systeemjournaal en de logs van de dienst op de serversHetznerHooguit 30 dagen
Server access logs, system journal and the service’s logsHetznerAt most 30 days

Versleuteling en sleutelsEncryption and keys

ToegangAccess

Auditlog en controleAudit log and oversight

Elke handeling op het dashboard en via de API staat in het auditlog van de organisatie: wie, wat, wanneer; bij de API de naam van de sleutel. Het register noteert per aanroep wie handelde. Toegangslogs bewaren we hooguit 30 dagen. Het openbare logboek is voor iedereen leesbaar en te verifiëren: register.everstamp.app/v1/log.

Every action in the dashboard and through the API is recorded in the organisation’s audit log: who, what, when; for the API, the name of the key. The registry records who acted on each call. Access logs are kept for at most 30 days. The public log is readable and recomputable by anyone: register.everstamp.app/v1/log.

Beschikbaarheid en herstelAvailability and recovery

Ontwikkeling en uitrolDevelopment and release

Het contract tussen app, register en dashboard is één bron met een vingerafdruk; elke wijziging gaat door de testsuites van alle onderdelen, en wordt vóór de release apart op beveiliging nagekeken, met eigen proeven. De server volgt een aparte tak die alleen met een release vooruitgaat. Elke release is met SSH ondertekend; de server installeert hem pas als hij de handtekening heeft nagemeten tegen een vaste lijst van vertrouwde sleutels, en weigert een release die niet nieuwer is dan wat er draait of daar niet op voortbouwt. Een release van het register gaat niet de deur uit als er een kwetsbaarheid van niveau CRITICAL of HIGH langer dan 90 dagen openstaat zonder beschreven maatregel, of als het contract dat de server laadt niet bij de bron hoort. Het dashboard wordt bij elke build op dezelfde manier op kwetsbaarheden nagekeken. Een pakket dat OSV als kwaadaardig kent, houdt de build van het dashboard altijd tegen; bij een release van het register telt een malwaremelding van GitHub altijd als rood. De verificatiepagina is een enkel bestand. Het enige wat het buiten uw browser doet, is ons register vragen of het de regel kent; een Content Security Policy in het bestand staat alleen de eigen scripts van dat bestand toe, en alleen een verbinding met ons register, zodat wat u controleert niet stiekem kan veranderen. Een link onder een volledig groene uitkomst gaat via ons register naar de site; die klik staat, zoals elke opvraag, hooguit dertig dagen in onze toegangslog. Uit diezelfde toegangslogs tellen we per dag hoe vaak de controlepagina en de deellinkpagina werden geopend, langs welke weg (QR, pdf of link) en door hoeveel verschillende bezoekers, en hoe vaak er werd doorgeklikt naar de site. Verschillende bezoekers onderscheiden we aan het IP-adres en de browser, alleen tijdens het tellen. We bewaren alleen de aantallen, zonder IP-adres, browser, dossier of deellink; die aantallen bewaren we zonder termijn, want ze zeggen niets over een persoon.

The contract between app, registry and dashboard is a single source with a fingerprint; every change goes through the test suites of all the components, and is reviewed separately for security before release, with its own tests. The server follows a separate branch that only advances with a release. Every release is signed with SSH; the server installs it only after checking the signature against a fixed list of trusted keys, and refuses a release that is not newer than what is running or does not build on it. A release of the registry does not go out while a CRITICAL or HIGH vulnerability has been open for more than 90 days without a documented mitigation, or when the contract the server loads does not match the source. The dashboard is checked for vulnerabilities the same way at every build. A package that OSV knows as malicious always stops the dashboard build; for a release of the registry, a malware alert from GitHub always counts as red. The verification page is a single file. The only thing it does outside your browser is ask our registry whether it knows the entry; a Content Security Policy in the file allows only that file’s own scripts, and only a connection to our registry, so that what you are checking cannot quietly change. A link under a fully green result goes through our registry to the website; that click is kept, like every request, for at most thirty days in our access log. From those same access logs we count per day how often the verification page and the share link page were opened, by which route (QR, pdf or link) and by how many different visitors, and how often someone clicked through to the site. We tell visitors apart by IP address and browser, only while counting. We keep only the numbers, without an IP address, browser, file or share link; we keep those numbers without a time limit, because they say nothing about a person.

Kwetsbaarheden en non-conformiteit meldenReporting vulnerabilities and non-conformance

Vond u een kwetsbaarheid, een afwijking in het bewijs, of een manifest van EverStamp dat niet aan de C2PA-specificatie voldoet? Mail security@everstamp.app. Dit adres staat ook in /.well-known/security.txt (RFC 9116) en is het meldadres uit ons C2PA-conformancerecord. U krijgt binnen twee werkdagen antwoord. Wie te goeder trouw onderzoekt en meldt, hoeft van ons geen juridische stappen te vrezen; noem ons alstublieft niet publiek voordat het is opgelost.

Found a vulnerability, a discrepancy in the evidence, or an EverStamp manifest that does not conform to the C2PA specification? Email security@everstamp.app. The address is also in /.well-known/security.txt (RFC 9116) and is the reporting address in our C2PA conformance record. You will have a reply within two working days. We will not take legal action against anyone who researches and reports in good faith; please do not name us publicly before it is resolved.

Misbruik of illegale inhoud melden. Vertrouwt u een verzoek of een deellink niet, of meent u dat een deellink of een bewaard dossier illegale inhoud bevat? Meld het via security@everstamp.app. Wat wij in een melding vragen en wat wij ermee doen, staat in artikel 8 van de voorwaarden. Een melding is voor ons geen reden om versleutelde inhoud te openen.

Reporting misuse or illegal content. Do you not trust a request or a share link, or do you believe that a share link or a stored file contains illegal content? Report it to security@everstamp.app. What we ask in a notice and what we do with it is in article 8 of the terms. A notice is not a reason for us to open encrypted content.

SubverwerkersSubprocessors

WieWaarvoorWaar
WhoWhat forWhere
Hetzner Online GmbHde server van het register en een tweede back-updoelDuitsland
Hetzner Online GmbHthe registry server and a second backup targetGermany
CloudflareDNS, versleutelde archieven van deellinks en leveringen, back-upkopieEU-jurisdictie (R2); Data Privacy Framework (Cloudflare is gecertificeerd) en standaardcontractbepalingen voor wat het buiten de EU verwerkt
CloudflareDNS, encrypted archives for share links and deliveries, backup copyEU jurisdiction (R2); Data Privacy Framework (Cloudflare is certified) and standard contractual clauses for anything it processes outside the EU
Supabasede dashboarddatabase (ook betalingen, facturen en supportvragen) en het inloggenEU-regio; standaardcontractbepalingen met Supabase Pte. Ltd. (Singapore)
Supabasethe dashboard database (including payments, invoices and support questions) and sign-inEU region; standard contractual clauses with Supabase Pte. Ltd. (Singapore)
Vercelhet dashboard en de websitedraait in Frankfurt; de hoofdvestigingen voor verwerking staan volgens de verwerkersovereenkomst in de VS (Data Privacy Framework en standaardcontractbepalingen)
Vercelthe dashboard and the websiteruns in Frankfurt; according to the data processing agreement the primary processing facilities are in the US (Data Privacy Framework and standard contractual clauses)
Amazon Web Services (KMS)de signeersleutel van EverStamp in een HSMFrankfurt (Data Privacy Framework en standaardcontractbepalingen)
Amazon Web Services (KMS)the EverStamp signing key in an HSMFrankfurt (Data Privacy Framework and standard contractual clauses)
Resende-mail voor inloggen, uitnodigingen, verzoeken, offerteaanvragen, contactberichten, betalingen, supportvragen, productnieuws en beveiligingsmeldingenverzending vanuit de EU; account-, log- en metagegevens in de VS (Data Privacy Framework en standaardcontractbepalingen)
Resendemail for sign-in, invitations, requests, quote requests, contact messages, payments, support questions, product news and security noticessent from the EU; account data, logs and metadata in the US (Data Privacy Framework and standard contractual clauses)
Google Workspaceonze mailboxen op everstamp.app, zoals info@, privacy@ en support@, met offerteaanvragen, contactberichten en supportvragenwereldwijd mogelijk; Cloud Data Processing Addendum (Data Privacy Framework en standaardcontractbepalingen)
Google Workspaceour mailboxes at everstamp.app, such as info@, privacy@ and support@, with quote requests, contact messages and support questionspossibly worldwide; Cloud Data Processing Addendum (Data Privacy Framework and standard contractual clauses)
Vercel Web Analyticspaginaweergaven op het dashboard en de website, zonder cookies: het adres van de pagina, zonder zoekterm en zonder de naam van de organisatie. Bij Vercel, volgens de instelling van ons abonnement daar (nu 12 maanden).als Vercel hierboven
Vercel Web Analyticspage views on the dashboard and the website, without cookies: the address of the page, without search terms and without the organisation’s name. At Vercel, under the setting of our plan there (now 12 months).as Vercel above
Sentry (Functional Software, Inc.)foutmeldingen van het dashboard, uit de server en de browser, via onze server verstuurd (de browser praat nooit rechtstreeks met Sentry) en opgeschoond: nooit headers, cookies, het IP-adres van de bezoeker of de ingelogde gebruiker; e-mailadressen, rekeningnummers, telefoonnummers, tokens, kenmerken (van ons en van Mollie), factuurnummers en de naam van de organisatie in een adres gaan eruit; bij uitzondering kan een stukje ingevoerde tekst meegaan, zoals een naam; bewaard volgens de instelling van ons abonnement daar (nu 30 dagen)EU-regio (Frankfurt); de verwerkersovereenkomst laat verwerking in de VS en andere landen toe (Data Privacy Framework en standaardcontractbepalingen)
Sentry (Functional Software, Inc.)error reports from the dashboard, from the server and the browser, sent through our server (the browser never talks to Sentry directly) and scrubbed: never headers, cookies, the IP address of the visitor or the signed-in user; email addresses, account numbers, phone numbers, tokens, identifiers (ours and those of Mollie), invoice numbers and the organisation name in an address are removed; exceptionally a piece of entered text can remain, such as a name; kept under the setting of our plan there (now 30 days)EU region (Frankfurt); the data processing agreement allows processing in the US and other countries (Data Privacy Framework and standard contractual clauses)

Zelfstandige verwerkingsverantwoordelijkenIndependent controllers

Deze partijen verwerken gegevens voor een eigen doel, als eigen verwerkingsverantwoordelijke; ze zijn geen subverwerkers in de zin van de voorwaarden.

These parties process data for their own purpose, as controllers in their own right; they are not subprocessors within the meaning of the terms.

WieWaarvoorWaar
WhoWhat forWhere
Applede toestelattestatie (App Attest) bij elke registratie vanaf een iPhone, en de app op iPhone (App Store)wereldwijd
Appledevice attestation (App Attest) on every registration from an iPhone, and the app on iPhone (App Store)worldwide
Google (toestelattestatie)de toestelattestatie (Android Key Attestation) bij elke registratie vanaf een Android-toestel, en de app op Android (Play)wereldwijd
Google (device attestation)device attestation (Android Key Attestation) on every registration from an Android device, and the app on Android (Play)worldwide
SK ID Solutions ASde gekwalificeerde tijdstempels (eIDAS) op dossiers, rapporten, foto's met een stempel per foto en het register, sinds 14 september 2026; krijgt van onze server alleen een hash, niets van de gebruiker, en levert daarmee een eigen dienst. Dossiers van daarvoor dragen een stempel van BOSA (Belgische overheid), die de controlepagina op dezelfde manier controleertEstland
SK ID Solutions ASthe qualified time stamps (eIDAS) on files, reports, photos with a per-photo stamp and the registry, since 14 September 2026; receives from our server a hash only, nothing about the user, and provides a service of its own with it. Files from before that date carry a stamp from BOSA (Belgian federal government), which the verification page checks the same wayEstonia
Mollie B.V.de betalingen voor Business: iDEAL, kaart en SEPA-incasso; de betaalgegevens voert de betaler zelf bij Mollie in, wij bewaren ze nietAmsterdam; voor verwerking buiten de EER gebruikt Mollie standaardcontractbepalingen
Mollie B.V.payments for Business: iDEAL, card and SEPA direct debit; the payer enters the payment details at Mollie, we do not keep themAmsterdam; for processing outside the EEA Mollie uses standard contractual clauses
Europese Commissie (VIES)de controle van het btw-nummer van een bedrijf buiten Nederland, voor de verlegging van de btwEU
European Commission (VIES)checking the VAT number of a company outside the Netherlands, for the VAT reverse chargeEU
Google (inloggen met Google)het inloggen op het dashboard, als iemand daarvoor kiest: Google ziet dat je bij EverStamp inlogt, en wij krijgen alleen account-id, e-mailadres, naam en het adres van de profielfoto (de scopes openid, email en profile)wereldwijd; Data Privacy Framework en standaardcontractbepalingen
Google (sign in with Google)signing in to the dashboard, for anyone who chooses it: Google sees that you sign in to EverStamp, and we receive only the account ID, email address, name and the address of the profile photo (the scopes openid, email and profile)worldwide; Data Privacy Framework and standard contractual clauses
Microsoft (inloggen met Microsoft)het inloggen op het dashboard, als iemand daarvoor kiest, met een persoonlijk account of een account van werk of school: Microsoft ziet dat je bij EverStamp inlogt, en wij krijgen alleen account-id, e-mailadres, of dat is geverifieerd, en de naam als die wordt meegestuurd (de scopes openid en email); geen Microsoft Graph. Bij een account van werk of school is ook de organisatie die het beheert verantwoordelijkwereldwijd; Data Privacy Framework en standaardcontractbepalingen
Microsoft (sign in with Microsoft)signing in to the dashboard, for anyone who chooses it, with a personal account or one from work or school: Microsoft sees that you sign in to EverStamp, and we receive only the account ID, email address, whether it is verified, and the name if it is sent (the scopes openid and email); no Microsoft Graph. For a work or school account, the organisation that manages it is responsible as wellworldwide; Data Privacy Framework and standard contractual clauses

Andere diensten, zonder persoonsgegevensOther services, without personal data

Deze diensten krijgen geen gegevens van gebruikers en zijn daarom geen subverwerkers in de zin van de voorwaarden.

These services receive no user data and are therefore not subprocessors within the meaning of the terms.

WieWaarvoorWaar
WhoWhat forWhere
GitHubde broncode, zonder persoonsgegevensVS
GitHubthe source code, without personal dataUS
ntfy.shmeldingen van onze wachter aan EverStamp, zonder gegevens van gebruikers; een melding blijft 12 uur staanniet opgegeven door de dienst
ntfy.shalerts from our watcher to EverStamp, without user data; an alert is kept for 12 hoursnot stated by the service
UptimeRobot s. r. o.controleert of onze openbare adressen antwoordenSlowakije; verwerking ook buiten de EER
UptimeRobot s. r. o.checks that our public addresses respondSlovakia; processing also outside the EEA

Vragen voor uw beoordeling: privacy@everstamp.app. EverStamp is een product van Digital Sandbox B.V.

Questions for your assessment: privacy@everstamp.app. EverStamp is a product of Digital Sandbox B.V.