Start free

Security

Security you can check, not a badge.

The documents below are the ones our own control matrix cites, published from the files rather than rewritten for a website — which means they still say which controls are evidenced and which are on paper.

The documents

Three questions a security review always asks, answered by the document that answers them internally.

Subprocessors

Every company that processes SignSealer customer data, what each one is given, and where it is.

Data retention and deletion

What is removed when an agreement is redacted, what stays so the evidence still proves what it proved, and when each happens.

Incident response

What counts as an incident, what happens in the first hour, and who we tell. Published including the line saying it has never been run.

What anyone can verify without asking us

Not a summary of how it works. The real certificate, checked by anyone holding its code, with no account: signsealer.com/verify.

A chain that breaks if edited

Each audit row's hash covers its own content and the hash before it, per customer. Removing or altering one breaks every row after it, and the engine checks the chain rather than assuming it.

Consent before the signature

Written as its own event. The engine refuses a signature from a signer who has not consented — it is not a checkbox stored on the signature row, which is the difference between evidence and a claim.

The text, fingerprinted

The document's body is stored on the document rather than referenced from a template, and its SHA-256 goes into every event. A template that changes later cannot change what was signed.

What our own staff cannot see

The support tool selects no document body, no signature value and no signer name, anywhere. Not as a policy: the queries do not contain those columns, and a test reads the source and fails if they appear. Every look at an account is recorded before the answer is returned.

Reporting something

Where to send it

security@signsealer.com, which is also what /.well-known/security.txt says. Tell us what you found and how to reproduce it. We will confirm we have it, and we will tell you what we did.

What we ask

Test against your own account and your own documents. Do not touch another customer's data, and do not run anything that degrades the service for the businesses using it. We have no bounty programme — we would rather say that than imply one.

Also worth reading

Evidence and audit trail

What is recorded on every agreement, why it is recorded that way, and what the product deliberately cannot do.

Privacy policy

What we collect as a business, what we process on a customer's behalf, and how someone asks for their data.

A hand holding a phone showing a document and a signature, outside a timber lakeside cabin, with two guests walking to the door with luggage.

Ready when the next guest is.

Free for the first 25 agreements a month. No card to start.