Jolly is operated by Sign With Jolly, LLC, an Indiana limited liability company. This page describes how we protect the information in Jolly. It is written for the people who have to ask: the compliance, IT, and vendor-management staff at the title companies, escrow offices, lenders, and signing services that use us, and the notaries who keep their working profile here.
We have written it plainly and we have not claimed anything we do not do. Where a control is not yet in place, we would rather you hear it from us than find it in a questionnaire.
Why this matters here
Loan packages are not ordinary files. A closing package routinely contains a borrower's Social Security number, account numbers, income, and property details — nonpublic personal information under the Gramm-Leach-Bliley Act. Most of our customers are financial institutions with their own obligations under the FTC Safeguards Rule, including an obligation to oversee the vendors who touch that data. We are one of those vendors, and we have built accordingly.
Hosting and infrastructure
Jolly runs on Render, a managed cloud platform, with data stored in MongoDB Atlas. Both are operated in the United States. We do not run our own servers, and we do not host customer data in any other region.
We do not operate a corporate network that touches production. There is no office file server holding customer documents, no shared drive with loan packages on it, and no copy of the production database on a laptop.
Encryption
In transit. All traffic to and from Jolly is encrypted with TLS (HTTPS). This includes the web application, our API, and every document upload and download. Plain HTTP is not served.
At rest. The database is encrypted at rest by MongoDB Atlas. Uploaded documents are held on encrypted managed storage at our hosting provider.
Access control
Access is enforced by the application on every request, not by hiding links in the interface.
- Separation by company. Every order, client, invoice, and roster entry belongs to one company. A request for a record outside your company does not return a permission error that confirms the record exists — it returns nothing at all.
- Separation by role. Company staff, client users, and notaries each see a different application. A client user sees the orders they placed. A notary sees the orders assigned to her, and her own profile, earnings, and records.
- Documents follow the order. An uploaded loan package is reachable only by the company that placed the order and the notary currently assigned to it, and only through an authenticated request tied to that order. Documents are not served from a public folder and cannot be reached by guessing a URL.
- Least privilege by default. A newly invited staff member gets the access their role requires and nothing more. Notary text alerts are off until the notary turns them on herself.
Authentication
- Passwords are stored only as bcrypt hashes. We cannot read your password, and neither can anyone who obtained a copy of our database.
- Sessions expire automatically and must be re-established by signing in.
- Failed sign-in attempts are rate limited per network address; successful sign-ins are not counted, so normal office use is never throttled while password guessing is stopped quickly.
- Account creation is rate limited and requires email verification before the account becomes usable.
- Password reset and account activation links are single-use, time-limited, and stored only as hashes — the link we email cannot be reconstructed from our database.
- A change to a notary's payment details never takes effect from a company's edit. It requires the notary's own confirmation from a link we email her.
What we deliberately do not store
- No full Social Security or EIN numbers. A notary's W-9 is kept as the document she uploads; only the last four digits are recorded separately, so she can tell which one is on file.
- No driver's licenses or government identification.
- No payment card data. Card details are entered directly into Stripe and never reach our servers or our database. We store only the card brand and last four digits that Stripe returns, for display.
- No borrower documents beyond the retention window (below).
Document retention and automatic deletion
Because loan packages carry sensitive information, they are deleted automatically rather than kept indefinitely. Each company sets its own retention window, and uploaded documents and scans are removed by an automatic sweep that many days after the signing date. The default is 10 days; the window can be set between 5 and 90 days.
The order's own history — the workflow, the activity log, the invoice record — survives deletion. Only the files are removed. Changing a signing date automatically moves the deletion deadline with it.
Application security
- Security response headers are applied to every response, including protections against clickjacking and MIME-type sniffing, and referrer restrictions. The server does not advertise its software.
- Database access goes through a schema layer with typed queries; user input is not concatenated into queries.
- Order and profile input is validated server-side. Validation in the browser is a convenience, never the control.
- Secrets and API keys are held in the hosting provider's environment configuration. They are not committed to source control and are not present in the application bundle sent to browsers.
- The application refuses to start if its signing secret is missing, rather than starting in a degraded state.
Availability and continuity
Jolly runs on managed infrastructure with provider-managed backups of the database. Application code is held in version control, and a previous version can be redeployed. We do not offer a contractual uptime guarantee today; our Terms of Use describe the service as provided without one, and we say so here rather than implying otherwise.
Monitoring and logging
We keep standard application and access logs for security and troubleshooting. Actions taken on an order — assignment, reassignment, edits, document uploads and sends, completion, messages — are recorded in that order's own activity log, which is visible to the company and forms an audit trail for the signing.
Subprocessors
These are the service providers that may process information on our behalf in order to run Jolly. Each acts on our instructions only and is not permitted to use the information for its own purposes. We update this list when it changes.
| Provider | What it does for Jolly | Information involved |
|---|---|---|
| Render | Application hosting and file storage | All platform data, including uploaded documents |
| Cloudflare (R2) | Object storage for files sent with the Send Documents tool | The PDF files a sender chooses to send; deleted automatically after 7 days |
| MongoDB Atlas | Database | Account, company, order, notary, and billing records |
| Stripe | Payment processing for company subscriptions and per-order fees | Company billing contact and payment card details, which are held by Stripe and never by Jolly |
| Resend | Transactional email delivery | Recipient names and email addresses, and the order details contained in the message |
| Twilio | Text message delivery | Mobile numbers of notaries who opted in, and the message text |
| Google (Places API) | Address autocomplete while typing an address | The partial address text being typed |
| Stadia Maps | Map tiles displayed in the browser when a map is shown | The map area being viewed; no account or order data is sent |
No advertising, analytics, or tracking. Jolly contains no advertising network, no analytics package, and no third-party tracking scripts. We do not sell personal information, and we do not share it for advertising. Mobile numbers and text-message consent are never shared with anyone for marketing purposes.
Personnel
Jolly is a small company. Access to production systems is limited to the personnel who require it to operate the service, under individual accounts. Everyone with access is bound by confidentiality obligations. Access is removed when it is no longer required.
Handling a security incident
We maintain a written incident response plan covering detection, containment, assessment, notification, and review. If a security incident affects your data, we will notify you without undue delay and in any event within 72 hours of confirming it, tell you what we know and what we are doing, and cooperate with your own notification obligations. Our Data Processing Addendum states this as a contractual commitment.
What we do not have yet
We would rather state this than let you discover it.
- No SOC 2 report or ISO 27001 certification. Jolly is a new platform and has not been through a third-party audit. We will tell you if that changes; we will not imply otherwise in the meantime.
- No contractual uptime commitment. See above.
- Some controls appropriate to a larger company — independent penetration testing, a formal bug bounty — are on our roadmap rather than in place today.
If a control you require is not listed on this page, ask us directly. A straight answer is worth more to both of us than a maybe.
Reporting a vulnerability
If you believe you have found a security vulnerability in Jolly, please email security@signwithjolly.com with enough detail to reproduce it. We will acknowledge your report, keep you updated while we investigate, and will not pursue action against anyone who reports a genuine issue in good faith, without accessing or altering other people's data, and without publicly disclosing it before we have had a reasonable opportunity to fix it.
Changes to this page
We update this page as our practices change; the date at the top shows the current version. Material changes affecting customers are communicated to account owners.
Contact
Security and vendor-review questions: security@signwithjolly.com. General questions: hello@signwithjolly.com.
Sign With Jolly, LLC · PO Box 4450, Carmel, IN 46082 · app.jollyorders.com
See also our Terms of Use, Privacy Policy, Data Processing Addendum, text-message program details, and accessibility statement.