Frequently asked questions
ReadSignFlow is a B2B compliance platform for workforce policy acknowledgement — it distributes policies, bulletins, and procedures to every employee and contractor, captures a signed acknowledgement of the exact version from each person, and exports audit-ready evidence on demand. It reaches office, frontline, and deskless staff over email, QR, and the recipient portal — including on a shared tablet — with no app and no corporate email required, and SMS and WhatsApp delivery is coming soon. This page answers the questions compliance, HR, and operations teams ask most — from how it differs from e-signature tools to security, pricing, and what recipients can expect.
Start free — up to 20 employees, no card · Sign in
ReadSignFlow is a B2B compliance platform for workforce policy acknowledgement — it distributes policies, bulletins, and procedures to every employee and contractor, captures a signed acknowledgement of the exact version from each person, and exports audit-ready evidence on demand. It reaches office, frontline, and deskless staff over email, QR, and the recipient portal — including on a shared tablet — with no app and no corporate email required, and SMS and WhatsApp delivery is coming soon. This page answers the questions compliance, HR, and operations teams ask most — from how it differs from e-signature tools to security, pricing, and what recipients can expect.
Getting started
What is ReadSignFlow?
ReadSignFlow is a B2B compliance platform for workforce policy acknowledgement — a purpose-built way to prove your people received, confirmed, and signed the policies, bulletins, and procedures they're required to. Organisations distribute a document to every employee and contractor over email, QR, and the recipient portal (SMS and WhatsApp coming soon), track who has opened, confirmed, and signed the exact version, and export audit-ready evidence in one click. It is operated by Astrolabix LLC and built for compliance, HR, risk, and operations teams — not a generic e-signature tool.
What is a read-and-sign (policy-acknowledgement) platform?
A read-and-sign (policy-acknowledgement) platform distributes policies, bulletins, and procedures to a workforce, captures a signed acknowledgement from each person behind a read gate, and stores tamper-evident, audit-ready evidence of it. Unlike a document store or a single e-signature envelope, it manages the whole cycle — target, deliver, remind, read-gate, sign, and prove — across office, frontline, and contractor staff. ReadSignFlow does this over email, QR, and the recipient portal, with SMS and WhatsApp delivery coming soon.
How is ReadSignFlow different from DocuSign or a generic e-signature tool?
E-signature tools are built for one-off transactions — a contract, an offer, a form sent to a handful of known signers. ReadSignFlow is built for sending the same policy to your whole workforce: it enforces a read gate before anyone can sign, chases stragglers automatically, reaches frontline workers who have no corporate email, and tracks completion across the full population rather than only the people who opened an envelope. The practical differences are reach, manager escalation with per-person compliance tracking, and a one-click audit pack — see the full comparison at readsignflow.com/compare/esignature.
How do I choose the best policy acknowledgement software?
For a regulated, frontline-heavy workforce, the best policy acknowledgement software reaches staff who have no corporate email, gates signing behind a read confirmation, escalates anyone still outstanding to their manager, and exports regulator-ready evidence on demand. Generic e-signature tools cover none of the first three. See the comparison at readsignflow.com/compare/esignature.
How long does it take to go live?
Self-serve, most teams launch their first campaign in an afternoon: upload a policy, import your recipients from a CSV, set a deadline, and send — ReadSignFlow handles delivery, reminders, and evidence from there. There is nothing to install and no infrastructure to stand up. Wiring your HRIS into the JML API is the part that takes days rather than an afternoon.
How do we migrate off paper or spreadsheet sign-off?
You upload your current policy as a PDF, import your people from a spreadsheet (or have your HRIS post them to the REST API), and launch a campaign — replacing the paper sheet and the manual chase in one step. Historic paper records can sit alongside the new digital trail, so you move to defensible proof without losing what you already have. Our From paper to proof guide walks through the switch from manual policy sign-off to audit-ready digital acknowledgement.
Do we need to install anything?
No. ReadSignFlow is cloud-based software your team uses in a browser, and recipients sign on their own phone with no app to download. Admins log in to the portal; recipients tap a secure magic-link — nothing to install on either side.
Reaching your workforce
Can it reach staff who have no corporate email?
Yes — this is the core of it. ReadSignFlow delivers a secure magic-link over email, printable QR posters, and the recipient portal (including on a shared tablet in a break room), so frontline, deskless, and contractor staff read and sign on their own phone with no app and no login. SMS and WhatsApp delivery is in integration and coming soon. It closes the biggest gap in workforce compliance: the people who never see a corporate inbox but still have to acknowledge every policy.
Which channels can you deliver over — email, SMS, WhatsApp, QR?
Email, QR posters, and the recipient portal deliver today, and you can mix them within a single campaign — email for office staff, QR posters for a shop floor or ramp with no personal devices (QR campaigns are an Enterprise feature). SMS and WhatsApp delivery is in integration and coming soon — the channels are built into the product but not sending yet, so don't date a rollout around them. Every live channel lands the same secure magic-link and feeds the same completion tracking and audit trail.
Which languages can recipients sign in?
The recipient experience is available in five languages — English, Spanish, French, German, and Portuguese — so deskless staff can read and acknowledge policies in their own language. Documents themselves are shown in the language you upload them in; ReadSignFlow translates the signing experience, not your policy text. Read-gating and evidence capture work identically whatever the language, so a Spanish-language acknowledgement is just as defensible as an English one.
How do QR posters and shared devices work?
For sites where staff share devices or have no personal email, you print a QR poster or leave a shared tablet open on the recipient portal at the entrance, break room, or ramp. A worker scans or taps, confirms their identity, reads the policy through the read gate, and signs — then the session clears for the next person. It is how a plant floor, store, or airside team reaches full acknowledgement without a single corporate inbox.
Does the recipient need an app or a password?
No app and no password. Recipients open a secure, single-use magic-link sent to them (or scanned from a QR poster, or opened on a shared device), confirm who they are, and sign — the link itself authenticates them. Nothing to download, no account to create, no password to forget.
Tracking, reminders & proof
How do I prove employees have read a policy?
Send it as a ReadSignFlow Read & Sign campaign. A read gate keeps the sign button locked until the recipient's device confirms they have reached the end of the document, and every acknowledgement records signer identity, intent, and a UTC timestamp in an append-only, tamper-evident event log. What you can put in front of an auditor is precise: this named person, from this device and IP address, confirmed reaching the end of this exact document version and acknowledged it at this moment. Export the campaign audit pack to hand it over: a completion report plus a signature record and a full event trail for every person.
How do I track employee policy acknowledgment?
From one real-time dashboard: every person moves through sent, delivered, read, and signed, with filters by department, site, and role, and a live exception list of exactly who hasn't signed yet. This compliance tracking works for any document — policies, SOPs, safety bulletins, handbooks — and feeds the completion reports your managers quote and your auditors test. Employee policy acknowledgment stops being a spreadsheet you maintain by hand and becomes a status you can see at a glance.
Can it automate reminders and escalations?
Yes — this is most of the time it saves. Reminders go out automatically as each person's deadline approaches (at T-7 days, T-3 days, and T-24 hours), quiet hours are respected, and anyone still outstanding is escalated to their manager. For SLA-driven notices, such as a safety alert with a short window, the escalation clock follows the SLA — and every reminder and escalation is itself logged as evidence.
What happens when a policy is updated to a new version?
Every document lives in a versioned library. When a new revision replaces the old one, you choose who must re-acknowledge — everyone, or only the affected roles — and ReadSignFlow launches the re-attestation, retires the superseded version, and ties each signature to the exact revision that person read. That matters because 'which version did they sign?' is usually the first question an auditor asks.
Can I see who hasn't signed?
Yes — the exception list is a first-class view, not a report you have to build. At any moment you can see exactly who is outstanding, filtered by team, site, manager, or role, and export it or fire a targeted reminder. It is the difference between knowing your completion rate and knowing the names behind it.
Does it stop people signing before they have been through the document?
Yes. A read gate keeps the sign button locked until the recipient has been through the document and their device confirms they reached the end, so an acknowledgement is an attestation that the policy was opened and read through — not a bare click. To be precise about what that is: the end-of-document confirmation comes from the recipient's own device, and ReadSignFlow does not claim to measure how long anyone spent reading. What it does record — who signed, when, from what device and IP address, against which document version, in an append-only tamper-evident log — is what makes the acknowledgement hard to challenge, and it is well beyond e-signature tools that capture a signature event alone.
Audit & evidence
What evidence do I get for an audit or inspection?
A one-click audit pack: the signed PDF for every person plus an append-only, tamper-evident event log covering delivery, opens, reads, reminders, escalations, and signatures. It is audit-ready documentation with a SHA-256 manifest, so a regulator or auditor can verify its integrity independently. The pack shows who signed exactly which version, when, and over which channel — defensible proof across your whole population, with no sampling.
Is the audit log tamper-evident?
Yes. The event log is append-only — entries can be added but never edited in place, and a record is removed only when your configured retention window expires (an erasure request anonymises the person; the record itself stays) — and each audit pack ships with a SHA-256 manifest that lets anyone verify the records haven't been altered since export. If a single byte changes, the hash won't match, so the trail either checks out in full or visibly doesn't.
How long are records retained?
Retention is a workspace setting rather than a plan tier: records are kept for 7 years by default, and you can set anything from 1 to 30 years to match your policy and regulator. When the window passes, event-log and delivery records are deleted and leavers' personal details are anonymised rather than removed wholesale — signed PDFs and acknowledgement records are kept, so completion evidence survives data minimisation. Records under an active legal hold are exempt until the hold is lifted.
Can I export signed PDFs in bulk?
Yes. You can export every signed PDF for a campaign in one action, alongside the event log and manifest, rather than downloading them one at a time. Whether it's ten people or ten thousand, the audit pack assembles the full set on demand.
What's in the one-click audit pack?
Three things: the signed, timestamped PDF for each recipient; the append-only event log of every delivery, open, read, reminder, escalation, and signature; and a SHA-256 manifest that proves the whole set is intact. Together they answer the auditor's questions — who, what version, when, and over which channel — without you assembling anything by hand.
Integrations & automation
Does it integrate with our HRIS or ATS?
Your HRIS or ATS pushes people and joiner/mover/leaver (JML) events to our REST API or webhooks. Workday, BambooHR, SuccessFactors and others can all do this; there is no native connector to install, and we never hold credentials for your HR system. Policy assignments then follow your staff automatically as they join, change role, or leave — new hires get their day-one pack, movers pick up newly required policies, and leavers are locked into the audit log.
What is JML automation?
JML stands for joiner–mover–leaver. Your HRIS (or your own middleware) posts those lifecycle events to our REST API or webhooks, and ReadSignFlow assigns the right policies automatically: joiners receive their onboarding bundle on day one, movers are given the policies their new role requires and retired from ones that no longer apply, and leavers' records are sealed into the audit trail. It keeps acknowledgement obligations correct without anyone editing a spreadsheet.
Is there an API and webhooks?
Yes, on Growth and Enterprise plans. A versioned REST API lets you create recipients, launch campaigns, and pull status and evidence programmatically, and HMAC-signed webhooks push events — signed, reminded, escalated — to your systems in real time. The HMAC signature lets your endpoint verify each event genuinely came from ReadSignFlow.
Do you support single sign-on?
Yes, from Starter upwards (single sign-on is not included on Free). Admins can sign in with your corporate identity through OpenID Connect, against providers such as Microsoft Entra ID and Google Workspace.
Security, data & compliance
Where is our data hosted, and is it secure?
Your data is US-hosted in a single region — an EU data region is planned (in progress) — on SmarterASP.NET, our only hosting provider today, which is named in the sub-processor list in our DPA. It is encrypted in transit (TLS) and at rest (AES-256), isolated per tenant so no customer can see another's data. We operate to SOC 2 Type II and ISO 27001 controls — formal certification is in progress — and every acknowledgement is written to an append-only, tamper-evident audit log. See readsignflow.com/security for the current detail.
Are you SOC 2 or ISO 27001 certified?
We operate to SOC 2 Type II and ISO 27001 controls — encryption, access control, per-tenant isolation, tamper-evident logging, and monitoring are all in place today — and formal independent certification is in progress. We're precise about this on purpose: we won't claim a certificate we don't yet hold. An independent penetration test has been carried out; we do not publish its date, the firm, the scope, or a retest cadence. Enterprise buyers can request our current security documentation during procurement from trust@readsignflow.com.
Is an electronic acknowledgement legally defensible?
Every acknowledgement captures signer identity, intent, a UTC timestamp, and a tamper-evident audit trail, and ReadSignFlow supports eIDAS (EU/UK) and the US ESIGN Act and UETA for enforceable electronic records. In practice, a challenge then has to contend with who signed, that they intended to, when, and proof the record hasn't changed. This is general information, not legal advice — for your jurisdiction and use case, confirm requirements with your own counsel.
Are you GDPR-compliant?
ReadSignFlow is designed to be GDPR-aligned and acts as a data processor on behalf of your organisation, which remains the data controller. A Data Processing Agreement (DPA) is available, and features such as configurable retention with anonymisation, per-tenant isolation, and access controls support your obligations. You decide what personal data enters the platform and for how long.
Who can see the data?
Each customer's data is isolated in its own tenant, enforced in the application layer, with database row-level security policies defined and ready to enforce, so one organisation can never see another's. Within your tenant, role-based access control (RBAC) limits what each admin can see and do — by role and, where you need it, by department or site. Recipients only ever see the documents assigned to them.
Do you have an uptime SLA?
We operate the platform to a 99.9% availability target on every plan. That is a target we run to, not a measured figure and not a warranty — we publish no measurement window, exclusions, or service credits against it. A contractual availability commitment with service credits is agreed in an Enterprise agreement. Current service state is on readsignflow.com/status.
Pricing & plans
How much does it cost?
ReadSignFlow is free forever for up to 20 employees — no card, no time limit. Paid policy acknowledgement software starts at Starter ($99/month billed annually, or $119 month-to-month, up to 100 employees), scales through Growth ($1.50 per active employee per month, or $1.20 on annual billing, with a $150/month minimum — $120/month on annual), and tops out at Enterprise (custom, with single sign-on, advanced security controls, and procurement support). Paid plans have no trial: every paid plan is charged at checkout, from day one (Growth at the 100-employee minimum), and the Free plan is the way to try the product. Every paid plan carries a 14-day money-back guarantee: cancel within 14 days of your first charge and that charge is refunded in full. Free has nothing to refund. Full plans at readsignflow.com/pricing.
Is the Free plan really free?
Yes — genuinely free forever for up to 20 employees, with no credit card and no time limit. It's a real working plan for small teams and for trying the full acknowledgement flow before you grow into a paid tier, not a crippled demo.
How does Growth pricing work?
Growth is $1.50 per active employee per month, dropping to $1.20 on annual billing, with a 100-employee minimum — $150/month, or $120/month on annual. The included comms allowance is per WORKSPACE, not per employee: 25,000 emails and 5,000 SMS a month however many people you have. SMS and WhatsApp delivery is still being integrated and is not sending yet, so those allowances are what the channels will include when they go live; beyond that allowance sending pauses rather than running up a surprise bill — top up instantly with an email, SMS, or WhatsApp capacity add-on and your limit lifts immediately. Like every paid plan, Growth has no trial: you enter your employee count at checkout and your card is charged from day one, for at least the 100-employee minimum.
Is there a free trial?
No — paid plans have no trial. The Free plan is free forever for up to 20 employees, with no card and no time limit, and it is the way to try the product. Every paid plan is charged at checkout, from day one: Starter for the plan you picked, and Growth — once you enter your employee count — for at least the 100-employee minimum. Every paid plan carries a 14-day money-back guarantee: cancel within 14 days of your first charge and that charge is refunded in full. Free has nothing to refund.
Can I get my money back?
Yes, within 14 days. Every paid plan carries a 14-day money-back guarantee: cancel within 14 days of your first charge and that charge is refunded in full. Free has nothing to refund. After that, cancellation takes effect at the end of the period you have already paid for and later fees are non-refundable except where the law requires otherwise — the binding wording is in our Terms at readsignflow.com/terms.
What counts as an active employee?
An active employee is any person you keep active in ReadSignFlow — employees and contractors alike — whether or not they are targeted by a campaign that month. People you have invited but who haven't joined yet, and people you mark as on leave, as leavers, or as deactivated, are not counted. Growth is priced on that count with a 100-employee minimum. Full details at readsignflow.com/pricing.
Can I switch plans?
Yes — you can move up or down as your team and needs change, and annual billing unlocks the lower Growth rate. Start free, and upgrade when you need more people or higher-tier features like SSO and the REST API, and talk to us any time about the right tier.
For people who received a link
My employer sent me a ReadSignFlow link — what is it?
It's a secure link your organisation uses to share a workplace policy or document with you and record that you confirmed reading it and acknowledged it. You read and sign on your phone — no app to install and no account password to create. See readsignflow.com/for-recipients for exactly what we record and what we'll never ask for.
What do you record when I sign?
We record that you opened and read the document, the version you saw, a timestamp, the channel you signed over, and — as part of the signed receipt — your IP address and your device and browser. That is the evidence your employer needs to show the policy was acknowledged. We don't use it to work out where you are, and we don't track your browsing or anything you do outside the document. The record belongs to your employer, who decides how long it is kept.
What will you never ask me for?
We will never ask you for a password, a payment or card details, your national ID number, or to download an app. A genuine ReadSignFlow request only ever asks you to confirm your identity to your employer's standard, read the document, and sign. If a message claiming to be us asks for money or a password, treat it as a scam.
Is it safe to sign on my phone?
Yes. The link is secure and single-use, the connection is encrypted, and you never create a password or install anything. If you're ever unsure a link is genuine, check with the person at your workplace who sent it before you tap — but the process itself is designed to be safe on any phone.
ReadSignFlow · Product · Pricing · Security · Solutions · Resources · Enterprise · vs. e-signature · FAQ · Customers · About · Careers · For recipients · Status · Contact us · Start free · Sign in
Privacy · Terms · DPA · Acceptable use · Recipient terms · Cookies