
Security
Security you can check, not a badge.
The documents our control matrix cites, published from the files rather than rewritten for the web, so they still say which controls are evidenced and which are on paper.
The documents
Three questions a security review always asks, answered by the document that answers them internally.
Subprocessors
Every company that processes SignSealer customer data, what each one is given, and where it is.
Data retention and deletion
What is removed when an agreement is redacted, what stays so the evidence still proves what it proved, and when each happens.
Incident response
What counts as an incident, what happens in the first hour, and who we tell. Published including the line saying it has never been run.
What anyone can verify without asking us
Not a summary of how it works. The real certificate, checked by anyone holding its code, with no account: signsealer.com/verify.
A chain that breaks if edited
Each audit row's hash covers its own content and the hash before it, per customer. Removing or altering one breaks every row after it, and the engine checks the chain rather than assuming it.
Consent before the signature
Written as its own event. The engine refuses a signature from a signer who has not consented — it is not a checkbox stored on the signature row, which is the difference between evidence and a claim.
The text, fingerprinted
The document's body is stored on the document rather than referenced from a template, and its SHA-256 goes into every event. A template that changes later cannot change what was signed.
What our own staff cannot see
The support tool selects no document body, no signature value and no signer name, anywhere. Not as a policy: the queries do not contain those columns, and a test reads the source and fails if they appear. Every look at an account is recorded before the answer is returned.
Reporting something
Where to send it
security@signsealer.com, which is also what /.well-known/security.txt says. Tell us what you found and how to reproduce it. We will confirm we have it, and we will tell you what we did.
What we ask
Test against your own account and your own documents. Do not touch another customer's data, and do not run anything that degrades the service for the businesses using it. We have no bounty programme — we would rather say that than imply one.
Also worth reading
Evidence and audit trail
What is recorded on every agreement, why it is recorded that way, and what the product deliberately cannot do.
Privacy policy
What we collect as a business, what we process on a customer's behalf, and how someone asks for their data.

Ready when the next guest is.
Free for the first 25 agreements a month. No card to start.