Including the ones we can't answer yet. KemDoc is in development — where the honest answer is “we don't know yet”, that's what it says.
You keep them. Read access, download, and audit-trail export stay open on a lapsed account — forever, on every tier. What stops is new activity: sending envelopes, vaulting new documents, and creating new share links.
No competitor makes this promise, because for all of them the document is a file they already emailed you. For KemDoc the vault is the product, which is exactly what makes the promise cost us something — and worth believing. Holding a small business's signed operating agreement hostage over a missed $9 is not a thing we're willing to do.
Yes. Identical cryptographic protection on every tier: the zero-knowledge vault, the PAdES seal, the RFC 3161 timestamp, and the Certificate of Completion. Free accounts are limited by volume, never by protection.
A privacy company that sells security as an upgrade has conceded its free users don't deserve security. We'd rather cap envelopes than ship a deliberately weaker default and call it a plan.
Not at rest. That's the precise answer, and we'd rather give you the precise one than a comfortable one. Documents in your vault are encrypted with keys we don't hold — we can't open them, and neither can anyone who breaches or subpoenas that storage.
What we can always see is metadata: that a document exists, its size, who it went to, and who opened or signed it, when, and from where. That's the record that makes a signature worth anything, and it can't be encrypted away from us and still function.
Anyone in this category claiming their servers never touch your document under any circumstance is describing a simpler product than the one you're being sold. Ask them where the signing happens.
You lose access — and that's the trade, stated plainly rather than buried. Zero-knowledge means there's no master key on our side to fall back on. A provider who can restore your documents after you've lost everything is a provider who could always read them.
Recovery options are presented at signup rather than hidden in a settings page, so it's a trade-off you make knowingly. Business plans add Shamir organisation escrow — a k-of-n split, so recovery needs several people in your organisation to agree, and never us.
In many places and for many document types, electronic signatures carry the same weight as ink — but that depends on your jurisdiction and on what's being signed. Some instruments, wills and certain property transfers among them, frequently can't be executed electronically at all.
We're not putting a blanket “legally binding worldwide” claim on a homepage. What KemDoc produces is a PAdES-sealed document, an RFC 3161 trusted timestamp, and a Certificate of Completion recording who did what and when. If you have a specific compliance regime to satisfy, ask before you rely on it and we'll tell you honestly whether we meet it yet.
One envelope is one document package sent out for signature, however many signers it needs and however many times they open it. Sending the same contract to three people to countersign is one envelope, not three.
We price on envelopes because it's the one thing that scales with the value you get and with our own variable cost. Seats don't, which is why paid plans don't charge for them.
Because per-seat pricing is what most people are trying to get away from. A ten-person company on Business pays $29 a month total; the same company on DocuSign is typically looking at somewhere between $150 and $400.
Paid plans include the seats the plan lists at no extra cost, and the envelope cap is what's actually constrained — so seats can't be abused into free capacity either.
No. They open a link in a browser and sign. No signup, no app, no plugin — the friction lands on you, once, not on every client you send to.
Encrypted on Cloudflare R2 object storage. You can export in bulk whenever you want — leaving should cost an afternoon, not a migration project.
Account details, and metadata about documents — that they exist, their size, and the audit trail of who accessed them and when. Not the contents of vaulted documents, because we can't decrypt them.
We respond to valid legal process, and we'd rather you know the exact shape of what that yields before you sign up than after.
KemitPass is a vault for credentials — passwords, keys, TOTP codes. KemDoc is for documents and the act of signing them. Same zero-knowledge principle, different job, separate products.
No date yet. It's in active development, and the waitlist hears first — both if it ships and if the plan changes.
Join the waitlist — replies to the first email come straight to us, and early questions shape what gets built.