Home / Security
Security at eVerbary
The documents people send us are birth certificates, court records and medical files. This page sets out where they are held, who can open them and what we do to keep that list short. It is written to be checked, not admired — if something here matters to your firm and is not answered, write to support@everbary.com and ask.
$24.95/page
Flat rate per page, up to 250 words. No hidden fees.
100% USCIS acceptance
Every certified translation is guaranteed to be accepted by USCIS.
24-hour delivery
Most 1-3 page documents are delivered within 24 hours. Same-day available.
Everything stays in the United States
Uploaded documents are held in Google Cloud Storage in the United States, and the service that receives orders runs on a server in New Jersey. Nothing is processed or stored outside the US.
This matters for firms with data residency obligations, and it is the answer we give on security questionnaires: there is no offshore leg in the path a document takes.
Who can open a document
Access is limited to eVerbary staff handling the order and to the single translator assigned to it. Translators see the files for the orders they are working on and nothing else. They are bound by confidentiality terms before they are given any work.
Files are reached through links that carry an unguessable token rather than sitting at a predictable address. Transport is TLS everywhere — the website, the customer portal, the order API and the links themselves.
We never see your card
Card details are entered directly into fields hosted by Stripe or PayPal and never touch an eVerbary server. We hold the fact that an order was paid and a reference number, not a card number. That is also why we cannot charge a card you have not entered yourself.
The order API
- API keys are stored as SHA-256 hashes. An export of our database hands nobody a working key, and a lost key is revoked rather than recovered.
- A key can read only the orders belonging to its own account. An order that belongs to someone else answers "not found" rather than "forbidden", so a key cannot be used to discover which orders exist.
- Webhook deliveries are signed with HMAC-SHA256 over a timestamp and the message body, so a receiving system can prove a notification came from us and reject a replayed one.
- Every endpoint is HTTPS only.
Who else is involved
We keep this list short on purpose, and it is complete. Google Cloud and Firebase host the application, the database and the documents. DigitalOcean hosts the order API. Stripe and PayPal process payments. Algolia powers search inside the staff and customer portals. Microsoft Clarity records anonymised site usage, and is configured to mask account, staff and portal pages so it never captures customer documents or personal data.
Keeping and deleting your files
We keep a completed order and its files so that you can download them again and so we can answer questions about work we did. If you want an order and its documents removed, write to support@everbary.com from the address that placed it and we will delete them, subject to any record we are legally required to keep.
What we collect and why is set out in our privacy policy.
Found a problem?
Report it and we will work with you: our vulnerability disclosure page sets out how to reach us, what we commit to, and our promise not to pursue researchers acting in good faith.
What we do not claim
eVerbary does not hold SOC 2, ISO 27001 or PCI DSS certification, and we would rather say so here than have you discover it in a questionnaire. Card handling sits with Stripe and PayPal, who are PCI compliant. If your firm requires a specific attestation before sending us work, tell us what it is — we would rather know than guess.
Frequently asked questions
Where exactly are our documents stored?
Google Cloud Storage, multi-region United States. The order API runs on a server in New Jersey. Nothing leaves the US.
Who can read a document we send?
eVerbary staff working the order and the one translator assigned to it. Nobody else, and translators only see their own assignments.
Do you store our credit card?
No. Card details go straight to Stripe or PayPal and never reach an eVerbary server. We hold a payment reference, not a card number.
Can you delete an order for us?
Yes. Email support@everbary.com from the address that placed it and we will delete the order and its files, subject to any record we must keep by law.
Are you SOC 2 certified?
No, and we say so plainly rather than implying otherwise. Our payment processors are PCI compliant. Tell us what your firm requires and we will tell you honestly whether we meet it.
How do we report a security problem?
Email support@everbary.com with "Security" in the subject. See our vulnerability disclosure page for what happens next and how quickly.
Questions about any of this?
Write to support@everbary.com and a person will answer.