When you ask someone to commission an affidavit or a statutory declaration, you're handing over some of the most personal paperwork you own — family details, finances, immigration history. This article explains, in plain terms, what happens to a file after you upload it to eNotaryPublic.ca, who can open it, and what we record when they do.
Encrypted on the way to us
Every page of the site and every upload travels over HTTPS. Your browser and our servers set up an encrypted connection (TLS) before anything is sent, and the site tells browsers to always use HTTPS for our domain (HTTP Strict Transport Security), so a connection can't quietly fall back to an unencrypted one.
Encrypted while it's stored
Before a document is written to storage, our application encrypts it with AES-256-GCM, a widely used authenticated encryption standard. That covers the files you upload, the completed document your professional produces, the completion certificate and session recordings. The same applies when our storage runs on an external, S3-compatible provider: the file is encrypted by our application before it's sent, so the storage provider only ever holds encrypted data.
GCM also detects tampering. If an encrypted file were altered in storage, it would fail to decrypt rather than quietly return modified content.
What "encrypted" does and doesn't mean here
Security wording is easy to stretch, so we want to be precise. Your documents are encrypted in transit (between your device and us) and at rest (in storage). They are not "end-to-end encrypted" in the strict technical sense, where only the sender and the final recipient hold the keys. Our platform holds the encryption keys, because it has to be able to show your document to the professional handling your request, add the jurat and signatures, and produce the finished PDF.
So the rest of our protections are about controlling — and recording — who is allowed to use that ability.
Who can open your document
Access is limited to the people who need it for your request:
- You, when you're signed in or using your secure case link.
- The professional assigned to your request.
- Authorized members of our staff, signed in to our admin console — for example to help with a support request. Staff and professional accounts can use authenticator-app two-factor sign-in.
Files aren't published at public addresses. When a link to a file is shared — for example in an email about your request — it's a signed link that expires after a short time. Until your request is complete, documents on it are shown to everyone other than staff and your assigned professional as a watermarked, view-only preview. Downloads of the clean file become available once the document is completed.
Session recordings have stricter rules still: only the professional who held the session and our administrators can view them. A link on its own isn't enough — the viewer must also be signed in as one of those people.
Every view is logged
Each time someone views or downloads a stored file through the platform, we record which document it was, who opened it (you, your professional, a staff member or a shared link), whether it was a view or a download, the time, and the IP address and browser that made the request.
Separately, the steps on your request — a professional accepting it, the session starting, the document being finalized, a file being deleted under our retention schedule — are written to an audit trail. Together, these records let us answer "who looked at this, and when?" with facts rather than assumptions.
Identity documents
In our current flow there's no ID upload: your professional checks your government-issued photo ID on camera during the session. Where ID images are on file, they're encrypted and access-controlled like any other document, and they follow a shorter retention schedule than completed documents.
Payments
Card details are entered into Stripe's secure payment fields and processed by Stripe. Card numbers aren't stored on our servers; we keep only what a receipt needs, such as the card brand and the last four digits.
How long we keep things
Documents are deleted automatically on a schedule that depends on what they are. Uploads from abandoned or cancelled requests, ID images, completed documents and session records each have their own retention period. A daily job removes files once their period ends and records each deletion in the audit trail. The periods are set out in our retention policy.
If something looks wrong
If you believe your document was opened by someone who shouldn't have seen it, contact us with your case number. Because file access is logged, we can check exactly what happened. You can read more about our overall approach on our security page and in our privacy policy.