Security & compliance

Trust built into every signature

Your documents carry sensitive information. We protect them with the same standards banks and hospitals rely on — and we describe what we do accurately rather than generously.

SOC 2 Type II

Independently audited security controls.

GDPR & CCPA

Privacy-first data handling worldwide.

eIDAS & ESIGN

Compliant e-signatures in the US and EU.

HIPAA aligned

Safe for sensitive health documents.

How it works

The four things that protect a document

Each of these is a specific mechanism rather than a marketing phrase. Here is what each one actually does.

Encryption everywhere

Documents are protected with 256-bit AES encryption at rest and TLS 1.3 in transit, so your agreements are unreadable to anyone but the intended parties.

Envelope encryption — each document gets a unique data key, itself encrypted by a master key held in a hardware security module that never releases it
TLS 1.3 with forward secrecy, so recorded traffic cannot be decrypted later even if a long-term key were compromised
Keys rotate on a fixed schedule without downtime, and every key access is logged and reviewed
Backups use the same key hierarchy as production and are never restored into non-production environments

Tamper-evident sealing

The instant signing finishes, we generate a unique cryptographic hash of the document. Any later change to a single pixel breaks the seal and is flagged.

SHA-256 computed over the final document bytes at completion, and again at send, giving a verifiable before-and-after pair
The completion certificate is signed with our private key, so its contents cannot be altered either
Anyone holding the signed PDF can recompute the hash independently — verification does not require us
Optional RFC 3161 trusted timestamps from an independent authority for documents where timing is legally significant

Complete audit trail

Every view, click, and signature is timestamped with the signer identity and IP address, producing a certificate that holds up in court.

Per-page view events with duration, which is the most frequently cited evidence when a signer claims they never saw a clause
Electronic-records consent capture with timestamp, as required by ESIGN
Every field completion logged individually and in order, reconstructing the session as a sequence
Certificates are generated once at completion and never regenerated, so the copy you download in three years is byte-identical to day one

You stay in control

Set expiration dates, require access codes, and revoke a document at any time. Data residency and retention rules are yours to configure.

Void a document at any point before completion; recipients immediately lose access
Per-document access codes and expiry windows for sensitive sends
Retention policies configurable per document type, so tax forms and offer letters can differ
Full export at any time — your records are never hostage to an active subscription
Identity

Know who actually signed

An audit trail proves what happened at our system boundary. Where you need stronger assurance about who was holding the device, add a verification step.

Standard

Email verification

The signing link is unique, single-recipient, and expires. Access is logged with IP and device. Included on every plan.

Standard

Access codes

Require a code you share out of band — by phone or in person — before the document opens. Neither the code nor its contents are stored in the audit trail.

Pro

SMS one-time passcode

A code sent to a phone number you specify. Adds a second channel, so an email compromise alone is not enough to sign.

Business

Knowledge-based authentication

Dynamic questions generated from public and credit records. Common for real estate and financial services where identity assurance is a regulatory expectation.

Business

Government ID verification

The signer photographs an ID document and a selfie; both are checked for authenticity and match. The images are retained only as long as your policy requires.

Business

SSO for internal signers

SAML 2.0 and OIDC against your own identity provider, so employees authenticate with the credentials and MFA you already enforce.

Built to stay up

A signature platform that is unavailable is a deal that does not close. These are the numbers we commit to and measure ourselves against.

99.99%
Uptime SLA

Measured monthly and published. Credits apply automatically if we miss it.

3
Availability zones

Every component runs across at least three zones with automatic failover.

< 15 min
Recovery point objective

Maximum data loss in a total-region failure scenario.

< 1 hr
Recovery time objective

Target time to restore service in a declared disaster.

Access control

Control who can do what

Most security incidents are access problems rather than cryptography problems. The controls that matter are the unglamorous ones — knowing who can send on behalf of your organisation, and removing that ability the day someone leaves.

SCIM provisioning is the piece teams most often skip and most often regret. Without it, deprovisioning depends on somebody remembering.

Role-based permissions with separate send, edit, and admin rights
SAML 2.0 and OIDC single sign-on, with SCIM user provisioning and deprovisioning
Enforced MFA for all administrative accounts, ours and yours
Session timeouts and device management configurable per organisation
Immutable admin activity log covering every permission and setting change
IP allowlisting for organisations that require it
Your data

Where it lives, how long, and who sees it

Where your data lives

Choose US, EU, UK, Canada, or Australia as your primary region. Documents and audit trails stay in the region you select and are not replicated outside it, which matters for organisations with data residency obligations.

How long we keep it

Retention is yours to configure per document type. We do not silently delete records, and we do not silently keep them either — the policy you set is the policy that runs, and it is visible in your admin settings.

What happens if you leave

Full export of every document and certificate in standard PDF, at any time, without contacting sales. Because certificates are embedded in the signed files themselves, exported records remain independently verifiable after your account closes.

What we can see

Automated systems process document contents to render pages, place fields, and generate hashes. Human access requires an explicit break-glass procedure limited to a small on-call group, generates an immutable audit record, and triggers a notification. In ordinary operation no employee reads your documents.

Certifications

What we hold, and what it covers

A badge on its own tells you very little. Scope is the part that matters, so here is ours.

StandardScopeDetail
SOC 2 Type IISecurity, Availability, ConfidentialityTwelve-month observation period across the full platform. The report is available under NDA — we would rather you read it than trust the badge.
ISO 27001Information security managementCertified ISMS covering our engineering, infrastructure, and operational processes, audited annually by an accredited body.
GDPREU & UK data protectionData processing agreement available to every customer, EU data residency on request, and support for access, export, and erasure requests.
CCPA / CPRACalifornia privacyWe do not sell personal information. Consumer rights requests are handled through the same tooling as GDPR requests.
ESIGN & UETAUS electronic signaturesSignature workflow, consent capture, and record retention meet the statutory requirements for enforceable electronic signatures in the US.
eIDASEU & UK electronic signaturesSignatures meet the Advanced Electronic Signature standard. Qualified signatures are available through accredited trust service providers.
HIPAAUS protected health informationWe sign business associate agreements and implement the required administrative, physical, and technical safeguards for PHI.
21 CFR Part 11FDA regulated recordsAvailable on request for life sciences customers, with the additional controls that regulation requires around record integrity and signature manifestation.
How we operate

The practices behind the certificates

Independent penetration testing

Full-scope external tests twice a year by a third-party firm, plus targeted testing on significant new features. Executive summaries are available to customers under NDA.

Vulnerability disclosure

A published policy and a safe harbour for good-faith researchers. Reports go to security@signthedoc.com and are acknowledged within one business day.

Incident response

A documented plan, rehearsed quarterly. Affected customers are notified directly and promptly per our contractual and regulatory obligations, and we publish a post-mortem for every incident that affected customers.

Secure development

Mandatory peer review, automated dependency and secret scanning on every commit, and static analysis in the build pipeline. Infrastructure changes above a defined risk threshold require a load test before deploy.

Personnel controls

Background checks where legally permitted, annual security training, least-privilege access granted on request and reviewed quarterly, and same-day revocation on departure.

Subprocessor management

A public list of every subprocessor with its purpose and location. Customers on notification lists get thirty days notice before we add one.

Straight answers

Security questions we get asked

Not in ordinary operation. Automated systems must process contents to render pages and generate hashes, but human access requires a break-glass procedure limited to a small on-call group, produces an immutable audit record, and triggers a notification. This is an access-control guarantee rather than a mathematical one, and we would rather describe it accurately than imply end-to-end encryption we do not provide.

Every signature comes with a court-admissible audit trail

Timestamps, IP addresses, and a unique document hash are recorded for every action — locked the moment signing completes. See exactly what that looks like.

See how it works →Read the full breakdown

Security questions or a vulnerability to report? security@signthedoc.com