Security
The documents below are the ones our own control matrix cites, published from the files rather than rewritten for a website — which means they still say which controls are evidenced and which are on paper.
Three questions a security review always asks, answered by the document that answers them internally.
Every company that processes SignSealer customer data, what each one is given, and where it is.
What is removed when an agreement is redacted, what stays so the evidence still proves what it proved, and when each happens.
What counts as an incident, what happens in the first hour, and who we tell. Published including the line saying it has never been run.
Not a summary of how it works. The real certificate, checked by anyone holding its code, with no account: signsealer.com/verify.
Each audit row's hash covers its own content and the hash before it, per customer. Removing or altering one breaks every row after it, and the engine checks the chain rather than assuming it.
Written as its own event. The engine refuses a signature from a signer who has not consented — it is not a checkbox stored on the signature row, which is the difference between evidence and a claim.
The document's body is stored on the document rather than referenced from a template, and its SHA-256 goes into every event. A template that changes later cannot change what was signed.
The support tool selects no document body, no signature value and no signer name, anywhere. Not as a policy: the queries do not contain those columns, and a test reads the source and fails if they appear. Every look at an account is recorded before the answer is returned.
security@signsealer.com, which is also what /.well-known/security.txt says. Tell us what you found and how to reproduce it. We will confirm we have it, and we will tell you what we did.
Test against your own account and your own documents. Do not touch another customer's data, and do not run anything that degrades the service for the businesses using it. We have no bounty programme — we would rather say that than imply one.
What is recorded on every agreement, why it is recorded that way, and what the product deliberately cannot do.
What we collect as a business, what we process on a customer's behalf, and how someone asks for their data.

Free for the first 25 agreements a month. No card to start.