Third Party Index

Snapshot 44523

Document
Security page
URL
https://signpaperless.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
64998 bytes
SHA-256 (raw)
faca8cb225efdb5c28204fa8ff2322794ee81581883ef21f0d03c0c9e96d4281
SHA-256 (normalized text)
3bc22139282aa9b8f34c62ac51d5e0b980741f98eced4354c81742f89cdc8572

Normalized text

Scripts and page chrome removed; this is what change detection compares.

A verifiable final document. A platform-applied digital seal and trusted timestamp help verify the completed PDF, while the audit trail records the signing activity of each recipient.
Platform-applied digital seal
PAdES and LTV
Adobe AATL-trusted certificate
Platform-applied digital sealing
After all recipients finish signing, SignPaperless applies a certificate-based digital seal to the completed PDF. The platform-applied seal protects document integrity and makes subsequent changes detectable.
Complete audit trail
The audit trail records the signer, timestamp, IP address, and document version for each signing event. This provides a clear record of the process.
PAdES and Long-Term Validation
Trusted timestamping and Long-Term Validation preserve the evidence needed to validate the platform-sealed, PAdES-compliant PDF after signing, including after the certificate expires.
Signature audit record
Recorded during the signing process
Signer
Verified recipient
Timestamp
UTC date & time
IP address
Origin recorded
Document
Version locked
Final PDF sealed with PAdES, trusted timestamping, Long-Term Validation, and an Adobe AATL-trusted platform certificate
Signing workflow
Completed documents are sealed and traceable
From delivery through completion, activity associated with each signing link is recorded in the audit trail. After all recipients finish, SignPaperless applies a platform digital seal to protect the final PDF.
Email-based signing access
A signing link is sent to the recipient's email address. Opening the link provides access to view and sign the assigned document.
Document version locking
The version presented to each recipient is locked during signing. After everyone finishes, a platform-applied digital seal makes later changes to the completed PDF detectable.
Envelope-level audit history
Events such as sending, viewing, signing, and declining are timestamped and recorded in the envelope history.
Certificate of completion
When all parties have signed, a certificate of completion is generated with the full signing record attached to the final document.
Platform safeguards
Infrastructure that protects your signing activity
Encryption, access controls, and application security measures work together to protect data at rest, in transit, and within the platform.
Document protection
Your documents stay encrypted and isolated
Documents and signatures are protected in transit, at rest, and within your account.
AES-256 encryption at rest
Stored documents are encrypted using AES-256, so the content remains unreadable without the appropriate encryption keys.
Encryption in transit
Data is encrypted while it travels between your device and our servers, which helps protect it from interception.
TLS 1.2+ on all endpoints
Connections to SignPaperless use TLS 1.2 or higher to protect data while it is being transmitted.
Tenant data isolation
Customer data is logically separated by tenant to prevent access across accounts.
Access control
Only authorized users reach your signing workflows
Authentication, permissions, and session controls help restrict document access to authorized users and requests.
Authenticated data access
Requests for protected data are authenticated before they are processed.
JWT session management
JSON Web Tokens are used to authenticate users and protect the integrity of active sessions.
Granular RBAC
Role-based permissions can be scoped to a workspace, team, or document, giving users access appropriate to their responsibilities.
Session and device controls
Inactivity timeouts, active-session visibility, and remote revocation provide additional control over account access.
Application security
The platform is hardened against common threats
Input validation and upload scanning keep malicious content from reaching your signing environment.
Input validation & sanitization
User input is validated and sanitized to help prevent SQL injection, cross-site scripting, and related attacks.
File upload validation
Uploaded documents are checked for file type and size, then scanned for malware before acceptance.
Found a security issue?
We welcome responsible reports from security researchers. Review our disclosure guidelines and contact our security team.
Responsible Disclosure policy