At eSigns, contracts and signatures carry legal and business weight, so protecting them is central to how we build and run our platform. This page describes the security practices and compliance standards behind our electronic signature, contract lifecycle management (CLM), and workflow automation services. For information on the legal validity of electronic signatures, see our Legality pages for USA and India.
1. Our Security Approach
- Defense in depth: Multiple layers of controls across application, network, data, and people.
- Least privilege: Access to systems and customer data is limited to those who need it and reviewed regularly.
- Security by design: Security reviews are part of our development lifecycle, not a final step.
- Continuous improvement: We test, monitor, and refine our controls on an ongoing basis.
2. Data Protection
Encryption
- In transit: All data moving between your browser or API client and eSigns is protected with TLS [1.2 or higher].
- At rest: Documents, signatures, and databases are encrypted using [AES-256].
- Key management: Encryption keys are managed through [AWS KMS / Azure Key Vault] with access controls and rotation.
Data isolation
Customer data is logically separated so that one customer's documents and data cannot be accessed by another.
Backups and recovery
- Automated encrypted backups [daily/continuous].
- Backups are stored in geographically separate locations.
- Disaster recovery plans are tested [annually]. Recovery objectives: RPO [X hours], RTO [X hours].
Data retention and deletion
Customers control retention settings for their documents. When data is deleted, or an account is closed, it is removed from active systems and then purged from backups on a rolling cycle, subject to legal retention requirements.
3. Document Integrity and Signature Security
- Tamper-evident documents: Signed documents are sealed with a cryptographic hash and [digital certificate], so any change after signing is detectable.
- Audit Trail: Every action is recorded with timestamps, IP addresses, device details, and event history, and included in a Certificate of Completion.
- Signer authentication options: Email link verification, one-time passcodes (email/SMS), access codes, [Aadhaar eSign via licensed providers], [Digital Signature Certificates], [government ID and liveness verification], and [knowledge-based authentication].
- Time stamping: [Trusted timestamp authority] is used to prove when a document was signed.
- Long-term validation: Signed PDFs retain verification data so signatures can be validated in the future.
4. Access Control and Authentication
- Role-based access control: Granular permissions for users, teams, templates, and workflows.
- Single Sign-On (SSO): SAML 2.0 / OIDC with [Okta, Microsoft Entra ID, Google Workspace, etc.].
- Multi-factor authentication (MFA): Available for all users [and enforceable by admins].
- Password security: Passwords are hashed and salted, and we support password policies and session timeouts.
- User provisioning: [SCIM] support for automated onboarding and offboarding.
- Internal access: Employee access to production systems requires MFA, is logged, and is approved on a need-to-know basis.
5. Infrastructure and Network Security
- Cloud hosting: Hosted on [AWS / Azure], in [regions, e.g., Mumbai, Hyderabad, N. Virginia], in facilities that hold [ISO 27001, SOC 2, and other] certifications.
- Network protection: Firewalls, network segmentation, private networking, and DDoS protection through [Cloudflare/provider].
- Web application firewall (WAF) and rate limiting to guard against common attacks.
- Hardening and patching: Systems follow secure baselines and are patched on a defined schedule, with critical vulnerabilities prioritized.
- Logging and monitoring: Centralized logs and alerting for suspicious activity, [24/7 monitoring].
6. Application Security
- Secure development lifecycle: Code review, dependency scanning, static and dynamic analysis, and secrets management.
- Penetration testing: Independent third-party testing at least [annually], with findings tracked to remediation.
- Vulnerability management: Regular scans and defined remediation timelines by severity.
- API security: Authenticated APIs with scoped tokens, rate limits, and webhook signature verification.
- Responsible disclosure: See Section 9.
7. Incident Response
We maintain a documented incident response plan covering detection, containment, investigation, remediation, and review.
- Security incidents are classified and escalated based on severity.
- Affected Customers are notified without undue delay and as required by contract and law, including [within X hours of confirming a personal data breach].
- We follow applicable reporting rules, including CERT-In Directions in India (incident reporting within 6 hours and log retention for 180 days) and state breach notification laws in the US.
- Post-incident reviews feed back into our controls.
8. Compliance and Certifications
| Framework |
Status |
What it covers |
| SOC 2 Type II |
[Certified] |
Security, availability, and confidentiality controls, independently audited |
| GDPR |
[Compliant] |
Protecting personal data such as names, emails, IP addresses, and timestamps. |
Audit reports, certificates, and security questionnaires are available to customers and prospects [under NDA at support@esigns.io].
9. Responsible Disclosure
We welcome reports from security researchers.
- Report to: support@esigns.io [and/or bug bounty platform link]
- Please include steps to reproduce, affected URLs, and potential impact.
- We will acknowledge reports within [2 business days] and keep you updated.
- Please avoid accessing others' data, degrading the service, or public disclosure before we have had a reasonable time to fix the issue.
- We will not pursue legal action against good-faith research that follows these guidelines.
- Our disclosure file is at [/.well-known/security.txt].
10. Data Residency and Cross-Border Transfers
- Customer Content is hosted in [regions available].
- Cross-border transfers rely on safeguards required by applicable law, described in our Privacy Policy and [Data Processing Agreement].
- Sector customers (banks, NBFCs, insurers, healthcare, government) with localization requirements should contact support@esigns.io to discuss options.
11. Subprocessors and Vendor Management
We use carefully selected subprocessors for hosting, email/SMS delivery, payments, identity verification, and support. Each is assessed for security and privacy before onboarding, bound by written agreements, and reviewed periodically. The current list is on [AWS/Azure] cloud servers, and we notify Customers of changes in advance.
12. People and Governance
- Background checks for employees where permitted by law.
- Security and privacy training at onboarding and [annually], including phishing awareness.
- Confidentiality agreements for all staff and contractors.
- Policies covering access control, acceptable use, change management, business continuity, and incident response, reviewed at least annually.
- Named security leadership: [CISO / Head of Security] and a Data Protection/Grievance Officer.
13. Availability and Reliability
- Uptime target: [99.9%] for production services, described in our [SLA].
- Redundancy: Multi-zone architecture to reduce single points of failure.
- Status page: Real-time status and incident history at [status.eSigns].
14. Customer Security Responsibilities
Security is shared. Customers should:
- Enable MFA and SSO, and manage user access and offboarding promptly.
- Choose signer authentication levels appropriate to document risk.
- Keep credentials and API keys confidential and rotate them regularly.
- Review the Audit Trail and sharing settings for sensitive documents.
- Keep access to sensitive documents limited to the people who need it.