Security
Last updated October 2026
PDF Sign handles contracts and personal data, so security is designed into the product. This page describes the controls in place today.
Document integrity
- Every uploaded PDF is validated (structure, not just its name or type), optionally malware-scanned, and fingerprinted with SHA-256. Originals are written once and never overwritten.
- Completed documents carry a PAdES digital seal (ETSI.CAdES.detached). PDF readers report any modification after sealing.
- Where a time-stamping authority is configured, the seal and the audit trail are timestamped under RFC 3161, so time does not depend on our server clock.
Audit trail
- Every significant action (sending, viewing, verification, consent, signing, downloads) is recorded with time, IP address and device.
- Events are hash-chained per agreement: each event's hash covers the previous one, so edits or deletions are detectable.
- The database rejects updates and deletes on audit records at the trigger level.
Signer authentication
- Personal signing links are HMAC-signed and can be invalidated per recipient.
- One-time codes (email or SMS) are stored only as keyed hashes, expire after 10 minutes and are limited to 5 attempts.
- Rate limits protect sign-in, codes, signing links and uploads.
Account security
- Passwords are hashed with Argon2id. Optional authenticator-app two-factor authentication with single-use recovery codes.
- Sessions are revocable: changing or resetting a password, or choosing “sign out everywhere”, ends every other session.
- Role-based permissions are checked on every request; every record is scoped to its organization.
Data protection
- All traffic uses TLS. Documents live in private object storage, encrypted at rest, and are only reachable via short-lived signed links after authorization.
- Secrets such as two-factor seeds are encrypted at the application layer (AES-256-GCM).
- Storage and databases can be deployed in Indian regions.
Reporting a vulnerability
If you believe you have found a security issue, please email security@ your deployment's domain with details. Please do not publicly disclose it before we have had a chance to respond.