Built to the standard auditors expect.
SOC 2 Type II and ISO 27001 controls (certification in progress), GDPR-aligned, EU and US data regions, SSO/SAML, encryption in transit and at rest, and eIDAS and US ESIGN/UETA signatures. The append-only, tamper-evident audit log is audit trail software in the strict sense: every acknowledgement event is recorded immutably and exported as audit-ready documentation on demand.
Security questions
Is ReadSignFlow SOC 2 and ISO 27001 certified?
We operate to SOC 2 Type II and ISO 27001 controls; formal certification is in progress. A control summary, and SOC 2 / penetration-test reports under NDA, are available to enterprise customers on request.
What encryption does ReadSignFlow use?
Data is encrypted in transit with TLS and at rest with AES-256, with strict per-tenant isolation at the database layer.
Where is my data stored?
Hosted in EU and US data regions. Cross-border transfers, where they occur, are covered by Standard Contractual Clauses and the UK Addendum.
Do you support SSO and MFA?
Yes — SSO via SAML 2.0 (Microsoft Entra, Google, and other IdPs) and multi-factor authentication, with SCIM provisioning on Enterprise.
Is the audit log tamper-evident?
Yes. The audit log is append-only and exported with a tamper-evident manifest, so every acknowledgement event can be independently verified.
Can I get a DPA and sub-processor list?
Yes. A Data Processing Agreement is available, and the current sub-processor list is available on request.
Product · Pricing · Security · Solutions · Resources · Book a demo