Our Security Posture
SignFlow Now is actively pursuing SOC 2 Type I and ISO 27001 certification through Vanta . We are not yet certified — the controls below reflect our current work-in-progress status as we build toward audit readiness. We will update this page when certifications are achieved.
Security Controls
Control Categories
Monitored continuously via Vanta against SOC 2 Trust Services Criteria and ISO 27001 Annex A controls. All categories are currently in progress — statuses will be updated as each is independently verified.
Access Control
Role-based access, MFA enforcement, least-privilege provisioning and de-provisioning procedures.
Data Encryption
AES-256 encryption at rest, TLS 1.3 in transit, HSM-backed key management with quarterly rotation.
Incident Response
Documented incident response plan, designated security owner, defined SLAs for detection and notification.
Vendor Management
Third-party vendor risk assessments, sub-processor agreements, and ongoing monitoring of critical suppliers.
Change Management
Peer code review, staging environment gating, and documented change approval processes for production.
Business Continuity
Recovery point and recovery time objectives defined, backup strategy tested, disaster recovery playbook documented.
Employee Security Training
Security awareness training at onboarding and annually, phishing simulation, and acceptable-use policies.
Logging & Monitoring
Centralised log aggregation, alerting on anomalous access patterns, and tamper-evident audit trails.
Risk Assessment
Annual risk register review, threat modelling for new features, and tracked remediation of identified risks.
What's Already True
Technical Safeguards, Live Today
The following apply to every document, signature, and piece of data on SignFlow Now right now — independent of any ongoing certification process.
AES-256 Encryption at Rest
Every document, signature, and piece of personal data is encrypted with AES-256-GCM at rest.
TLS 1.3 in Transit
All data in transit is protected by TLS 1.3 with HSTS enforced across all endpoints.
SHA-256 Audit Trail
Every document is hashed with SHA-256 at signing. Any post-signature modification is instantly detectable.
UK/EU Data Hosting
Data is stored on AWS in eu-west-2 (London). GDPR-compliant with full data processing agreements.
PKI Digital Certificates
X.509 certificates issued per signing session, uniquely binding each signatory to their document.
Compliance Automation via Vanta
Security controls are monitored continuously via Vanta as we work toward SOC 2 Type I and ISO 27001.
Security Contact
For vulnerability reports, security questions from prospects or customers, or requests for additional security documentation (penetration test summaries, DPAs, sub-processor lists), please contact our security team directly.
security@signflownow.comWe aim to respond to security enquiries within 24 hours.