Security
Last updated: 19 August 2026
You are about to route the most sensitive paperwork of your life — identity documents, proof of funds, your solicitor’s emails — through one place. This page is a plain account of how that place is built to protect them. Everything below is something the system does, not something we intend to do.
Encrypted, both ways
Everything you send travels over HTTPS, with HSTS set so a browser will only ever connect securely. Every document you store is encrypted at rest with AES-256 before it is written to disk. In transit and at rest, your files are never sitting in the clear.
Every open is on the record
When you share a document, each time it is opened or downloaded is written to a tamper-evident access log — a hash chain, where every entry seals the one before it, so a later edit to any entry breaks the chain and is detectable. The entries cannot be edited after the fact by anyone, including us. You can see exactly who opened what, and when.
You decide who sees what
Your transaction is private by default. Other people reach it only when you invite them. When you share a single document, you send a link that expires, that you can revoke at any moment, and that you set to view-only or download — and every use of it is logged. A revoked or expired link stops working immediately, on the server, not just in the page.
Mail you can trust
Your transaction has its own email address. Mail from the people already on your transaction is filed automatically; mail from anyone else is held for your reviewrather than filed, so a stranger who guesses the address cannot inject a message into your record. A message whose sender fails the checks that prove an email really came from the domain it claims (SPF, DKIM and DMARC) is treated as unverified, not trusted — which is how a forged “our bank details have changed” from a look-alike of your solicitor is caught rather than believed.
Bank details, watched
Payment-redirection fraud — a criminal swapping the bank details in a completion email — is the single most damaging thing that can happen in a purchase. When you verify your solicitor’s account once, by phone, Chainkeep records only the sort code and the last four digits — enough to recognise those details again, never enough to pay from. From then on, every message that mentions bank details is checked against what you verified, and anything that differs is flagged loudly, before you send a penny.
Attachments checked
Every file that arrives — uploaded or emailed in — is scanned for malware before it reaches you. If the scanner cannot run for any reason, the file is refused rather than passed through unchecked.
We hold less than you’d expect
We never store a full bank account number, and we store no card or payment details at all. Your password is kept only as a bcrypt hash — we could not tell you what it is. You can add two-factor sign-in, with one-time recovery codes that only you ever see. Your product usage is measured with first-party analytics that live in our own database: no third-party tracking SDK, no advertising network, and property addresses and personal details never leave in the process.
Your data stays yours
You can export your entire record at any time, and you can delete your account and its data whenever you choose. If a purchase falls through, your identity and financial documents stay with you to carry into the next one — they belong to you, not to the house.
What we don’t claim
We are not a bank and we never move your money. Chainkeep organises your transaction and warns you; it does not provide legal or financial advice. No system is beyond every possible attack, and we don’t pretend otherwise — what we can tell you is exactly how this one is built, which is what this page is for. If you ever believe you have sent money to a fraudster, call your bank immediately and then Action Fraud on 0300 123 2040.