Frequently asked questions

ReadSignFlow is a B2B compliance platform for workforce policy acknowledgement — it distributes policies, bulletins, and procedures to every employee and contractor, proves each person read and signed the exact version, and exports audit-ready evidence on demand. It reaches office, frontline, and deskless staff over email, SMS, WhatsApp, QR, and kiosk, with no app and no corporate email required. This page answers the questions compliance, HR, and operations teams ask most — from how it differs from e-signature tools to security, pricing, and what recipients can expect.

ReadSignFlow is a B2B compliance platform for workforce policy acknowledgement — it distributes policies, bulletins, and procedures to every employee and contractor, proves each person read and signed the exact version, and exports audit-ready evidence on demand. It reaches office, frontline, and deskless staff over email, SMS, WhatsApp, QR, and kiosk, with no app and no corporate email required. This page answers the questions compliance, HR, and operations teams ask most — from how it differs from e-signature tools to security, pricing, and what recipients can expect.

Getting started

What is ReadSignFlow?

ReadSignFlow is a B2B compliance platform for workforce policy acknowledgement — a purpose-built way to prove your people have read and signed the policies, bulletins, and procedures they're required to. Organisations distribute a document to every employee and contractor over email, SMS, WhatsApp, QR, and kiosk, track who has read and signed the exact version, and export audit-ready evidence in one click. It is operated by ReadFlowSign LLC and built for compliance, HR, risk, and operations teams — not a generic e-signature tool.

What is a read-and-sign (policy-acknowledgement) platform?

A read-and-sign (policy-acknowledgement) platform distributes policies, bulletins, and procedures to a workforce, proves each person read and acknowledged them, and stores tamper-evident, audit-ready evidence of it. Unlike a document store or a single e-signature envelope, it manages the whole cycle — target, deliver, remind, read-gate, sign, and prove — across office, frontline, and contractor staff. ReadSignFlow does this over email, SMS, WhatsApp, QR, and kiosk.

How is ReadSignFlow different from DocuSign or a generic e-signature tool?

E-signature tools are built for one-off transactions — a contract, an offer, a form sent to a handful of known signers. ReadSignFlow is built for sending the same policy to your whole workforce: it enforces a read gate before anyone can sign, chases stragglers automatically, reaches frontline workers who have no corporate email, and tracks completion across the full population rather than only the people who opened an envelope. The practical differences are reach, automated reminders and escalation, and a one-click audit pack — see the full comparison at readsignflow.com/compare/esignature.

How long does it take to go live?

Most teams launch their first campaign within days, not through a lengthy implementation project. You upload a policy, import or sync your recipients, set a deadline, and send — ReadSignFlow handles delivery, reminders, and evidence from there. There is nothing to install and no infrastructure to stand up.

How do we migrate off paper or spreadsheet sign-off?

You upload your current policy as a PDF, import your people from a spreadsheet or an HRIS sync, and launch a campaign — replacing the paper sheet and the manual chase in one step. Historic paper records can sit alongside the new digital trail, so you move to defensible proof without losing what you already have. Our From paper to proof guide walks through the switch from manual policy sign-off to audit-ready digital acknowledgement.

Do we need to install anything?

No. ReadSignFlow is cloud-based software your team uses in a browser, and recipients sign on their own phone with no app to download. Admins log in to the portal; recipients tap a secure magic-link — nothing to install on either side.

Reaching your workforce

Can it reach staff who have no corporate email?

Yes — this is the core of it. ReadSignFlow delivers a secure magic-link over SMS, WhatsApp, QR posters, and shared kiosks, so frontline, deskless, and contractor staff read and sign on their own phone with no app and no login. It closes the biggest gap in workforce compliance: the people who never see a corporate inbox but still have to acknowledge every policy.

Which channels can you deliver over — email, SMS, WhatsApp, QR, kiosk?

All five: email, SMS, WhatsApp, QR codes, and shared kiosks. You can mix them within a single campaign — email for office staff, SMS or WhatsApp for field teams, and QR posters or a kiosk for a shop floor or ramp with no personal devices. Every channel lands the same secure magic-link and feeds the same completion tracking and audit trail.

Which languages can recipients sign in?

The recipient experience is multilingual, including English and Spanish, with more languages available, so deskless staff can read and acknowledge policies in their own language. Read-gating and evidence capture work identically whatever the language, so a Spanish-language acknowledgement is just as defensible as an English one.

How do QR posters and shared kiosks work?

For sites where staff share devices or have no personal email, you print a QR poster or set up a kiosk at the entrance, break room, or ramp. A worker scans or taps, confirms their identity, reads the policy through the read gate, and signs — then the session clears for the next person. It is how a plant floor, store, or airside team reaches full acknowledgement without a single corporate inbox.

Does the recipient need an app or a password?

No app and no password. Recipients open a secure, single-use magic-link sent to them (or scanned from a QR poster or kiosk), confirm who they are, and sign — the link itself authenticates them. Nothing to download, no account to create, no password to forget.

Tracking, reminders & proof

How do I track employee policy acknowledgment?

From one real-time dashboard: every person moves through sent, delivered, read, and signed, with filters by department, site, and role, and a live exception list of exactly who hasn't signed yet. This compliance tracking works for any document — policies, SOPs, safety bulletins, handbooks — and feeds the completion reports your managers quote and your auditors test. Employee policy acknowledgment stops being a spreadsheet you maintain by hand and becomes a status you can see at a glance.

Can it automate reminders and escalations?

Yes — this is most of the time it saves. Reminders go out automatically as each person's deadline approaches (at T-7 days, T-3 days, and T-24 hours), quiet hours are respected, and anyone still outstanding is escalated to their manager. For SLA-driven notices, such as a safety alert with a short window, the escalation clock follows the SLA — and every reminder and escalation is itself logged as evidence.

What happens when a policy is updated to a new version?

Every document lives in a versioned library. When a new revision replaces the old one, you choose who must re-acknowledge — everyone, or only the affected roles — and ReadSignFlow launches the re-attestation, retires the superseded version, and ties each signature to the exact revision that person read. That matters because 'which version did they sign?' is usually the first question an auditor asks.

Can I see who hasn't signed?

Yes — the exception list is a first-class view, not a report you have to build. At any moment you can see exactly who is outstanding, filtered by team, site, manager, or role, and export it or fire a targeted reminder. It is the difference between knowing your completion rate and knowing the names behind it.

Does it enforce that people actually read before they sign?

Yes. A read gate requires recipients to move through the document — with page-level read tracking — before the sign button unlocks, so an acknowledgement means the policy was actually opened and reviewed, not just clicked. This is a key difference from e-signature tools that record only a signature event, and it makes each acknowledgement far harder to challenge.

Audit & evidence

What evidence do I get for an audit or inspection?

A one-click audit pack: the signed PDF for every person plus an append-only, tamper-evident event log covering delivery, opens, reads, reminders, escalations, and signatures. It is audit-ready documentation with a SHA-256 manifest, so a regulator or auditor can verify its integrity independently. The pack shows who signed exactly which version, when, and over which channel — defensible proof across your whole population, with no sampling.

Is the audit log tamper-evident?

Yes. The event log is append-only — entries can be added but never edited or deleted — and each audit pack ships with a SHA-256 manifest that lets anyone verify the records haven't been altered since export. If a single byte changes, the hash won't match, so the trail either checks out in full or visibly doesn't.

How long are records retained?

Retention is configurable to your policy and regulator, typically anywhere from one to ten years. When a record reaches the end of its retention window it is anonymised rather than hard-deleted, so aggregate audit history and completion evidence survive even after personal data is removed. This lets you meet data-minimisation duties without destroying the proof an auditor may later ask for.

Can I export signed PDFs in bulk?

Yes. You can export every signed PDF for a campaign in one action, alongside the event log and manifest, rather than downloading them one at a time. Whether it's ten people or ten thousand, the audit pack assembles the full set on demand.

What's in the one-click audit pack?

Three things: the signed, timestamped PDF for each recipient; the append-only event log of every delivery, open, read, reminder, escalation, and signature; and a SHA-256 manifest that proves the whole set is intact. Together they answer the auditor's questions — who, what version, when, and over which channel — without you assembling anything by hand.

Integrations & automation

Does it integrate with our HRIS or ATS?

Yes. ReadSignFlow syncs people and joiner/mover/leaver (JML) events from systems like Workday, BambooHR, and SuccessFactors, plus a REST API and webhooks for anything else. Policy assignments then follow your staff automatically as they join, change role, or leave — new hires get their day-one pack, movers pick up newly required policies, and leavers are locked into the audit log.

What is JML automation?

JML stands for joiner–mover–leaver. ReadSignFlow listens to those lifecycle events from your HRIS or API and assigns the right policies automatically: joiners receive their onboarding bundle on day one, movers are given the policies their new role requires and retired from ones that no longer apply, and leavers' records are sealed into the audit trail. It keeps acknowledgement obligations correct without anyone editing a spreadsheet.

Is there an API and webhooks?

Yes. A versioned REST API lets you create recipients, launch campaigns, and pull status and evidence programmatically, and HMAC-signed webhooks push events — signed, reminded, escalated — to your systems in real time. The HMAC signature lets your endpoint verify each event genuinely came from ReadSignFlow.

Do you support SSO and SCIM?

Yes. Enterprise plans include SSO via SAML 2.0 with identity providers such as Microsoft Entra ID and Google, plus SCIM for automated user provisioning and de-provisioning. Admins sign in with your corporate identity, and accounts are created and removed in step with your directory.

Security, data & compliance

Where is our data hosted, and is it secure?

Your data is hosted in EU and US data regions and encrypted in transit (TLS) and at rest (AES-256), isolated per tenant so no customer can see another's data. It sits behind SOC 2 Type II and ISO 27001 controls, with an append-only, tamper-evident audit log. See readsignflow.com/security for the current detail.

Are you SOC 2 or ISO 27001 certified?

We operate to SOC 2 Type II and ISO 27001 controls — encryption, access control, per-tenant isolation, tamper-evident logging, and monitoring are all in place today — and formal independent certification is in progress. We're precise about this on purpose: we won't claim a certificate we don't yet hold. Enterprise buyers can request our current security documentation during procurement.

Is an electronic acknowledgement legally defensible?

Every acknowledgement captures signer identity, intent, a UTC timestamp, and a tamper-evident audit trail, and ReadSignFlow supports eIDAS (EU/UK) and the US ESIGN Act and UETA for enforceable electronic records. In practice, a challenge then has to contend with who signed, that they intended to, when, and proof the record hasn't changed. This is general information, not legal advice — for your jurisdiction and use case, confirm requirements with your own counsel.

Are you GDPR-compliant?

ReadSignFlow is designed to be GDPR-aligned and acts as a data processor on behalf of your organisation, which remains the data controller. A Data Processing Agreement (DPA) is available, and features such as configurable retention with anonymisation, per-tenant isolation, and access controls support your obligations. You decide what personal data enters the platform and for how long.

Who can see the data?

Each customer's data is isolated in its own tenant, enforced at the database layer, so one organisation can never see another's. Within your tenant, role-based access control (RBAC) limits what each admin can see and do — by role and, where you need it, by department or site. Recipients only ever see the documents assigned to them.

Pricing & plans

How much does it cost?

ReadSignFlow is free forever for up to 20 employees — no card, no time limit. Paid policy acknowledgement software starts at Starter ($99/month flat, up to 100 employees), scales through Growth ($1.50 per active employee per month, or $1.20 on annual billing, with a $150/month minimum), and tops out at Enterprise (custom, with SSO/SAML, SCIM, data residency, and procurement support). A 14-day full-feature trial is available on Starter and Growth — full plans at readsignflow.com/pricing.

Is the Free plan really free?

Yes — genuinely free forever for up to 20 employees, with no credit card and no time limit. It's a real working plan for small teams and for trying the full acknowledgement flow before you grow into a paid tier, not a crippled demo.

How does Growth pricing work?

Growth is $1.50 per active employee per month, dropping to $1.20 on annual billing, with a $150/month minimum. Each active employee includes a monthly allowance of 30 emails and 5 SMS; usage beyond that is billed at our cost plus 5%, so you're never marked up heavily on messaging. You pay for the people who are actually active in a given month, not a fixed seat count.

Is there a free trial?

Yes — a 14-day full-feature trial on the Starter and Growth plans, with no functionality held back. And if up to 20 employees covers you, the Free plan lets you keep going with no time limit at all.

What counts as an active employee?

Broadly, an active employee is someone who is assigned to or engages with a campaign during the billing month — not everyone sitting in your directory. Someone on leave or not currently targeted by any campaign doesn't count toward your active total, so the price tracks real usage rather than raw headcount. The exact definition for your plan is set out at readsignflow.com/pricing and in your contract.

Can I switch plans?

Yes — you can move up or down as your team and needs change, and annual billing unlocks the lower Growth rate. Start free or on a trial, upgrade when you need more people or Enterprise features like SSO and data residency, and talk to us any time about the right tier.

For people who received a link

My employer sent me a ReadSignFlow link — what is it?

It's a secure link your organisation uses to share a workplace policy or document with you and record that you've read and acknowledged it. You read and sign on your phone — no app to install and no account password to create. See readsignflow.com/for-recipients for exactly what we record and what we'll never ask for.

What do you record when I sign?

We record that you opened and read the document, the version you saw, a timestamp, and the channel you signed over — the evidence your employer needs to show the policy was acknowledged. We don't track your location, your browsing, or anything you do outside the document. The record belongs to your employer, who decides how long it is kept.

What will you never ask me for?

We will never ask you for a password, a payment or card details, your national ID number, or to download an app. A genuine ReadSignFlow request only ever asks you to confirm your identity to your employer's standard, read the document, and sign. If a message claiming to be us asks for money or a password, treat it as a scam.

Is it safe to sign on my phone?

Yes. The link is secure and single-use, the connection is encrypted, and you never create a password or install anything. If you're ever unsure a link is genuine, check with the person at your workplace who sent it before you tap — but the process itself is designed to be safe on any phone.

Product · Pricing · Security · Solutions · Resources · Book a demo

ReadSignFlow on LinkedIn, YouTube, Instagram, and Facebook.