Legal Center
Security Overview
An overview of the safeguards and shared responsibilities surrounding the service.
- Effective Date
- August 3, 2026
- Last Revised
- August 3, 2026
- Version
- 1.0
1. Purpose
This overview describes the safeguards currently implemented in Diversified Check Studio and the responsibilities shared between us and our customers.
This page is maintained by Diversified Check Studio to answer common security questions. It is a factual description of enabled controls, not a certification, audit report, or independent verification.
2. Architecture Summary
Diversified Check Studio is a browser-based application. Application servers, the managed database, authentication, and file storage are operated by established cloud providers. Categories of providers appear in the Subprocessors and Service Providers document.
The software does not connect to banking networks, does not transmit payment instructions, and does not move funds. Printing occurs from the customer's own browser to the customer's own printer.
3. Encryption
- Traffic between your browser and the service is encrypted in transit using current TLS.
- Stored data is encrypted at rest by the managed platform.
- Sensitive values, including bank account numbers and stored license keys, receive an additional layer of AES-256-GCM application-level encryption before they are written to the database.
- Sensitive values are masked in the interface by default and are revealed only through an explicit, audited action.
4. Access Control
- Every record is scoped to an account through database row level security, so one account cannot read another account's data.
- Role based access control governs what each user may do within an account.
- Permissions are enforced on the server, not only in the interface.
- Roles are stored separately from user profiles to prevent privilege escalation through profile edits.
- Administrative platform functions are restricted to designated global administrators.
5. Authentication
- Passwords are hashed by the managed authentication provider and are never stored in readable form.
- Two-factor authentication using authenticator applications is available, with recovery codes and optional trusted device recognition.
- Account administrators can require two-factor authentication for their users, and platform policy can require it more broadly.
- Sensitive operations, such as revealing a stored license key, require re-authentication.
6. File and Asset Storage
Signature images, logos, and other uploaded assets are stored in private buckets. Access requires an authenticated, authorized request, and links generated for viewing are short lived.
7. Logging and Auditing
The platform records security-relevant events, including sign-in activity, permission changes, license issuance and revocation, sensitive value access, print job creation, and administrative actions. Audit records are retained as described in the Data Retention and Deletion Policy.
8. Availability and Backups
The managed database platform performs automated backups. Customers may also produce their own encrypted export through the backup and export tools in the software. We recommend that customers retain their own copies of critical designs and records.
9. Change Management
Application changes are reviewed before release, database changes are applied through versioned migrations, and security-affecting defects are prioritized for correction.
10. Vulnerability Reporting
Suspected vulnerabilities should be reported under the Responsible Disclosure Policy. Please do not disclose a suspected issue publicly before we have had a reasonable opportunity to respond.
11. Shared Responsibility
We are responsible for the security of the platform. Customers are responsible for how they use it, including:
- Maintaining strong, unique credentials and enabling two-factor authentication.
- Granting each user only the access they need and removing users promptly when access should end.
- Protecting printed check stock, magnetic toner supplies, and printed output physically.
- Confirming bank information with the financial institution and controlling who may authorize a check run.
- Reporting suspected unauthorized access without delay.
Physical control of printed checks is the customer's responsibility. Software controls cannot prevent misuse of a printed instrument once it leaves the printer.
12. What We Do Not Claim
We do not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or similar certification for Diversified Check Studio, and we do not claim that any system is free of vulnerabilities. No method of transmission or storage is completely secure.
13. Incident Notification
If we determine that a security incident has affected customer data, we will notify affected customers without undue delay and provide the information reasonably available, consistent with applicable law and any applicable Data Processing Addendum.
14. Changes to This Overview
This overview is updated as controls change. The Last Revised date and version number will be updated when it changes.
15. Contact
Security questions may be directed to:
Diversified Check Studio
A product of Diversified SaaS, Inc.
Diversified SaaS, Inc. is a wholly owned subsidiary of Diversified Universal LLC.
6212 US Highway 6, Suite 184
Portage, IN 46368-5057
Email: CustomerService@DiversifiedCheckStudio.com
Phone: 1 (833) 990-7297
WhatsApp: 1 (833) 990-7297