Snapshot 44523
Normalized text
Scripts and page chrome removed; this is what change detection compares.
A verifiable final document. A platform-applied digital seal and trusted timestamp help verify the completed PDF, while the audit trail records the signing activity of each recipient. Platform-applied digital seal PAdES and LTV Adobe AATL-trusted certificate Platform-applied digital sealing After all recipients finish signing, SignPaperless applies a certificate-based digital seal to the completed PDF. The platform-applied seal protects document integrity and makes subsequent changes detectable. Complete audit trail The audit trail records the signer, timestamp, IP address, and document version for each signing event. This provides a clear record of the process. PAdES and Long-Term Validation Trusted timestamping and Long-Term Validation preserve the evidence needed to validate the platform-sealed, PAdES-compliant PDF after signing, including after the certificate expires. Signature audit record Recorded during the signing process Signer Verified recipient Timestamp UTC date & time IP address Origin recorded Document Version locked Final PDF sealed with PAdES, trusted timestamping, Long-Term Validation, and an Adobe AATL-trusted platform certificate Signing workflow Completed documents are sealed and traceable From delivery through completion, activity associated with each signing link is recorded in the audit trail. After all recipients finish, SignPaperless applies a platform digital seal to protect the final PDF. Email-based signing access A signing link is sent to the recipient's email address. Opening the link provides access to view and sign the assigned document. Document version locking The version presented to each recipient is locked during signing. After everyone finishes, a platform-applied digital seal makes later changes to the completed PDF detectable. Envelope-level audit history Events such as sending, viewing, signing, and declining are timestamped and recorded in the envelope history. Certificate of completion When all parties have signed, a certificate of completion is generated with the full signing record attached to the final document. Platform safeguards Infrastructure that protects your signing activity Encryption, access controls, and application security measures work together to protect data at rest, in transit, and within the platform. Document protection Your documents stay encrypted and isolated Documents and signatures are protected in transit, at rest, and within your account. AES-256 encryption at rest Stored documents are encrypted using AES-256, so the content remains unreadable without the appropriate encryption keys. Encryption in transit Data is encrypted while it travels between your device and our servers, which helps protect it from interception. TLS 1.2+ on all endpoints Connections to SignPaperless use TLS 1.2 or higher to protect data while it is being transmitted. Tenant data isolation Customer data is logically separated by tenant to prevent access across accounts. Access control Only authorized users reach your signing workflows Authentication, permissions, and session controls help restrict document access to authorized users and requests. Authenticated data access Requests for protected data are authenticated before they are processed. JWT session management JSON Web Tokens are used to authenticate users and protect the integrity of active sessions. Granular RBAC Role-based permissions can be scoped to a workspace, team, or document, giving users access appropriate to their responsibilities. Session and device controls Inactivity timeouts, active-session visibility, and remote revocation provide additional control over account access. Application security The platform is hardened against common threats Input validation and upload scanning keep malicious content from reaching your signing environment. Input validation & sanitization User input is validated and sanitized to help prevent SQL injection, cross-site scripting, and related attacks. File upload validation Uploaded documents are checked for file type and size, then scanned for malware before acceptance. Found a security issue? We welcome responsible reports from security researchers. Review our disclosure guidelines and contact our security team. Responsible Disclosure policy