Security

Last updated October 2026

PDF Sign handles contracts and personal data, so security is designed into the product. This page describes the controls in place today.

Document integrity

  • Every uploaded PDF is validated (structure, not just its name or type), optionally malware-scanned, and fingerprinted with SHA-256. Originals are written once and never overwritten.
  • Completed documents carry a PAdES digital seal (ETSI.CAdES.detached). PDF readers report any modification after sealing.
  • Where a time-stamping authority is configured, the seal and the audit trail are timestamped under RFC 3161, so time does not depend on our server clock.

Audit trail

  • Every significant action (sending, viewing, verification, consent, signing, downloads) is recorded with time, IP address and device.
  • Events are hash-chained per agreement: each event's hash covers the previous one, so edits or deletions are detectable.
  • The database rejects updates and deletes on audit records at the trigger level.

Signer authentication

  • Personal signing links are HMAC-signed and can be invalidated per recipient.
  • One-time codes (email or SMS) are stored only as keyed hashes, expire after 10 minutes and are limited to 5 attempts.
  • Rate limits protect sign-in, codes, signing links and uploads.

Account security

  • Passwords are hashed with Argon2id. Optional authenticator-app two-factor authentication with single-use recovery codes.
  • Sessions are revocable: changing or resetting a password, or choosing “sign out everywhere”, ends every other session.
  • Role-based permissions are checked on every request; every record is scoped to its organization.

Data protection

  • All traffic uses TLS. Documents live in private object storage, encrypted at rest, and are only reachable via short-lived signed links after authorization.
  • Secrets such as two-factor seeds are encrypted at the application layer (AES-256-GCM).
  • Storage and databases can be deployed in Indian regions.

Reporting a vulnerability

If you believe you have found a security issue, please email security@ your deployment's domain with details. Please do not publicly disclose it before we have had a chance to respond.