Jolly — Security Overview

Last updated September 22, 2026  ·  Terms of Use  ·  Privacy Policy  ·  Data Processing Addendum

Jolly is operated by Sign With Jolly, LLC, an Indiana limited liability company. This page describes how we protect the information in Jolly. It is written for the people who have to ask: the compliance, IT, and vendor-management staff at the title companies, escrow offices, lenders, and signing services that use us, and the notaries who keep their working profile here.

We have written it plainly and we have not claimed anything we do not do. Where a control is not yet in place, we would rather you hear it from us than find it in a questionnaire.

Why this matters here

Loan packages are not ordinary files. A closing package routinely contains a borrower's Social Security number, account numbers, income, and property details — nonpublic personal information under the Gramm-Leach-Bliley Act. Most of our customers are financial institutions with their own obligations under the FTC Safeguards Rule, including an obligation to oversee the vendors who touch that data. We are one of those vendors, and we have built accordingly.

Hosting and infrastructure

Jolly runs on Render, a managed cloud platform, with data stored in MongoDB Atlas. Both are operated in the United States. We do not run our own servers, and we do not host customer data in any other region.

We do not operate a corporate network that touches production. There is no office file server holding customer documents, no shared drive with loan packages on it, and no copy of the production database on a laptop.

Encryption

In transit. All traffic to and from Jolly is encrypted with TLS (HTTPS). This includes the web application, our API, and every document upload and download. Plain HTTP is not served.

At rest. The database is encrypted at rest by MongoDB Atlas. Uploaded documents are held on encrypted managed storage at our hosting provider.

Access control

Access is enforced by the application on every request, not by hiding links in the interface.

Authentication

What we deliberately do not store

Document retention and automatic deletion

Because loan packages carry sensitive information, they are deleted automatically rather than kept indefinitely. Each company sets its own retention window, and uploaded documents and scans are removed by an automatic sweep that many days after the signing date. The default is 10 days; the window can be set between 5 and 90 days.

The order's own history — the workflow, the activity log, the invoice record — survives deletion. Only the files are removed. Changing a signing date automatically moves the deletion deadline with it.

Application security

Availability and continuity

Jolly runs on managed infrastructure with provider-managed backups of the database. Application code is held in version control, and a previous version can be redeployed. We do not offer a contractual uptime guarantee today; our Terms of Use describe the service as provided without one, and we say so here rather than implying otherwise.

Monitoring and logging

We keep standard application and access logs for security and troubleshooting. Actions taken on an order — assignment, reassignment, edits, document uploads and sends, completion, messages — are recorded in that order's own activity log, which is visible to the company and forms an audit trail for the signing.

Subprocessors

These are the service providers that may process information on our behalf in order to run Jolly. Each acts on our instructions only and is not permitted to use the information for its own purposes. We update this list when it changes.

ProviderWhat it does for JollyInformation involved
RenderApplication hosting and file storageAll platform data, including uploaded documents
Cloudflare (R2)Object storage for files sent with the Send Documents toolThe PDF files a sender chooses to send; deleted automatically after 7 days
MongoDB AtlasDatabaseAccount, company, order, notary, and billing records
StripePayment processing for company subscriptions and per-order feesCompany billing contact and payment card details, which are held by Stripe and never by Jolly
ResendTransactional email deliveryRecipient names and email addresses, and the order details contained in the message
TwilioText message deliveryMobile numbers of notaries who opted in, and the message text
Google (Places API)Address autocomplete while typing an addressThe partial address text being typed
Stadia MapsMap tiles displayed in the browser when a map is shownThe map area being viewed; no account or order data is sent

No advertising, analytics, or tracking. Jolly contains no advertising network, no analytics package, and no third-party tracking scripts. We do not sell personal information, and we do not share it for advertising. Mobile numbers and text-message consent are never shared with anyone for marketing purposes.

Personnel

Jolly is a small company. Access to production systems is limited to the personnel who require it to operate the service, under individual accounts. Everyone with access is bound by confidentiality obligations. Access is removed when it is no longer required.

Handling a security incident

We maintain a written incident response plan covering detection, containment, assessment, notification, and review. If a security incident affects your data, we will notify you without undue delay and in any event within 72 hours of confirming it, tell you what we know and what we are doing, and cooperate with your own notification obligations. Our Data Processing Addendum states this as a contractual commitment.

What we do not have yet

We would rather state this than let you discover it.

If a control you require is not listed on this page, ask us directly. A straight answer is worth more to both of us than a maybe.

Reporting a vulnerability

If you believe you have found a security vulnerability in Jolly, please email security@signwithjolly.com with enough detail to reproduce it. We will acknowledge your report, keep you updated while we investigate, and will not pursue action against anyone who reports a genuine issue in good faith, without accessing or altering other people's data, and without publicly disclosing it before we have had a reasonable opportunity to fix it.

Changes to this page

We update this page as our practices change; the date at the top shows the current version. Material changes affecting customers are communicated to account owners.

Contact

Security and vendor-review questions: security@signwithjolly.com. General questions: hello@signwithjolly.com.
Sign With Jolly, LLC · PO Box 4450, Carmel, IN 46082 · app.jollyorders.com

See also our Terms of Use, Privacy Policy, Data Processing Addendum, text-message program details, and accessibility statement.