Trust
Security
Last updated 2026-09-01
This page describes what Sign actually does, not a checklist of certifications we haven't earned. We aren't SOC 2 or ISO 27001 certified. If that's a hard requirement for your organization, Sign isn't the right tool yet.
In transit
Every connection to Sign is HTTPS, enforced with HSTS so a browser won't even attempt an insecure connection on repeat visits. Traffic between your browser and our servers is encrypted the entire way.
Documents and files
Uploaded documents and signed PDFs are stored in Cloudflare R2, encrypted at rest. Signature images and completed documents are only accessible through a signed, token-gated link, either your own authenticated session or a recipient's unique signing link, never a public URL.
The database
The application connects to its production database with a restricted role that can read and write data but cannot alter the schema, drop a table, or run arbitrary DDL. A separate, higher-privilege credential exists only for running migrations and is never deployed to the running application.
Passwords and sessions
Passwords are hashed with bcrypt; we never store or can recover your plaintext password. Sessions are signed JWTs. Sensitive actions (signup, password reset, sending an envelope, changing a Stripe key) are rate-limited to slow down automated abuse.
The audit trail
Every view, consent, signature, and decline on an envelope is timestamped and logged with the signer's IP address, and the document is hashed before and after signing. That record is what makes a signature defensible, not just the image of it. See how it works for the full signing flow.
Payments
Billing is handled entirely by Stripe. Sign never receives, stores, or has access to your card number; Stripe's hosted checkout handles that directly.
Email verification
An account must verify its email address before it can send an envelope to anyone. This is meant to make Sign a less useful tool for impersonation and phishing, not just a formality.
Found a security issue?
We'd rather hear about it directly than find out from a support ticket. Contact details are on your account/billing page, or reach out however you normally would. See also our privacy policy and terms of service.