SOC 2 Type I & ISO 27001 — In Progress

Our Security Posture

SignFlow Now is actively pursuing SOC 2 Type I and ISO 27001 certification through Vanta . We are not yet certified — the controls below reflect our current work-in-progress status as we build toward audit readiness. We will update this page when certifications are achieved.

SOC 2 Type I — In Progress
ISO 27001 — In Progress

Security Controls

Control Categories

Monitored continuously via Vanta against SOC 2 Trust Services Criteria and ISO 27001 Annex A controls. All categories are currently in progress — statuses will be updated as each is independently verified.

In Progress

Access Control

Role-based access, MFA enforcement, least-privilege provisioning and de-provisioning procedures.

In Progress

Data Encryption

AES-256 encryption at rest, TLS 1.3 in transit, HSM-backed key management with quarterly rotation.

In Progress

Incident Response

Documented incident response plan, designated security owner, defined SLAs for detection and notification.

In Progress

Vendor Management

Third-party vendor risk assessments, sub-processor agreements, and ongoing monitoring of critical suppliers.

In Progress

Change Management

Peer code review, staging environment gating, and documented change approval processes for production.

In Progress

Business Continuity

Recovery point and recovery time objectives defined, backup strategy tested, disaster recovery playbook documented.

In Progress

Employee Security Training

Security awareness training at onboarding and annually, phishing simulation, and acceptable-use policies.

In Progress

Logging & Monitoring

Centralised log aggregation, alerting on anomalous access patterns, and tamper-evident audit trails.

In Progress

Risk Assessment

Annual risk register review, threat modelling for new features, and tracked remediation of identified risks.

What's Already True

Technical Safeguards, Live Today

The following apply to every document, signature, and piece of data on SignFlow Now right now — independent of any ongoing certification process.

AES-256 Encryption at Rest

Every document, signature, and piece of personal data is encrypted with AES-256-GCM at rest.

TLS 1.3 in Transit

All data in transit is protected by TLS 1.3 with HSTS enforced across all endpoints.

SHA-256 Audit Trail

Every document is hashed with SHA-256 at signing. Any post-signature modification is instantly detectable.

UK/EU Data Hosting

Data is stored on AWS in eu-west-2 (London). GDPR-compliant with full data processing agreements.

PKI Digital Certificates

X.509 certificates issued per signing session, uniquely binding each signatory to their document.

Compliance Automation via Vanta

Security controls are monitored continuously via Vanta as we work toward SOC 2 Type I and ISO 27001.

Security Contact

For vulnerability reports, security questions from prospects or customers, or requests for additional security documentation (penetration test summaries, DPAs, sub-processor lists), please contact our security team directly.

security@signflownow.com

We aim to respond to security enquiries within 24 hours.