Security practices

Straight answers for your security review.

This page explains the safeguards SignItSure has today and how documents are handled. We do not make claims for controls we have not independently verified.

Account access

Workspace roles limit who can manage documents and settings. Account holders may turn on authenticator-app multi-factor authentication. Once enabled, a current code is required before signed-in workspace actions continue.

Signing links

Senders choose an expiry from one hour to seven days, can add an access code, and can revoke a request. Recipient signing links are separate from the signed-in workspace.

Short-lived document handling

Files are held while a signing workflow needs them. After completion, original files and AI working data are removed. Signed copies remain available only during a short delivery window described in the product.

Signing record

The completed package includes the signed document and an audit certificate. The record includes the signer’s name, email, signing time, consent, and available connection details.

What we do not claim

SignItSure does not currently claim SOC 2 certification, SAML single sign-on, automatic company-wide MFA enforcement, or a legal guarantee that every document will be enforceable. We will update this page only when a control is implemented and verified.

Security questions and support

Send security questions, a vendor questionnaire, or a request to report a potential issue tosupport@signitsure.com. Please do not include customer documents or secrets in an initial security report.

Last updated: August 2026.