Built to the standard auditors expect.
SOC 2 Type II and ISO 27001 controls (certification in progress), GDPR-aligned, US-hosted (single region), single sign-on, encryption in transit (TLS 1.2 or 1.3) and at rest with AES-256, and eIDAS simple electronic signatures (SES, Article 25 — we do not issue advanced or qualified signatures) with US ESIGN/UETA support. Production runs on SmarterASP.NET in the United States — our only hosting provider today, named in the DPA sub-processor list. An independent penetration test has been carried out; we publish no test date, firm, scope, or retest cadence. We operate to a 99.9% availability target — a target, not a warranty. The append-only, tamper-evident audit log is audit trail software in the strict sense: entries are never edited in place, a record is removed only when the configured retention window expires (an erasure request anonymises the person rather than deleting the record), and every acknowledgement event is exported as audit-ready documentation on demand. Security questionnaires and vulnerability reports go to trust@readsignflow.com.
Start free — up to 20 employees, no card · Sign in
Security questions
Is ReadSignFlow SOC 2 and ISO 27001 certified?
We operate to SOC 2 Type II and ISO 27001 controls; formal certification is in progress. Our DPA and its sub-processor list are published at readsignflow.com/dpa; a detailed control summary is available on request from trust@readsignflow.com, and SOC 2 reports will be shared under NDA once the audit completes. An independent penetration test has been carried out — we do not publish its date, the firm, the scope, or a retest cadence.
What encryption does ReadSignFlow use?
Data is encrypted in transit with TLS 1.2 or TLS 1.3 and at rest with AES-256, with strict per-tenant isolation enforced in the application layer, and database row-level security policies defined and ready to enforce.
Where is my data stored?
US-hosted (single region). Production runs on SmarterASP.NET in the United States — our only hosting provider today, named in the sub-processor list at readsignflow.com/dpa. An EU data region is planned (in progress). Cross-border transfers, where they occur, are covered by Standard Contractual Clauses and the UK Addendum.
Do you support SSO and MFA?
Yes — OpenID Connect single sign-on (Microsoft Entra, Google) and multi-factor authentication.
Is the audit log tamper-evident?
Yes. The audit log is append-only and exported with a tamper-evident manifest, so every acknowledgement event can be independently verified for an evidence pack.
Can I get a DPA and sub-processor list?
Yes. A Data Processing Agreement is available, and our current sub-processor list is published inside it at readsignflow.com/dpa.
Do you publish an uptime commitment?
We operate the platform to a 99.9% availability target. It is a target, not a measured figure and not a warranty: we publish no measurement window, exclusions, or service credits against it. A contractual availability commitment with service credits is agreed in an Enterprise agreement.
Who do we contact about security?
trust@readsignflow.com — security questionnaires, control documentation, and vulnerability reports, which are answered within 48 hours. Sales, support and procurement stay on info@readsignflow.com.
Legal & data processing
Data Processing Agreement · Privacy Policy · Terms of Service · Acceptable Use Policy · Recipient Terms · info@readsignflow.com · trust@readsignflow.com
info@ for sales, procurement and the contractual documents; trust@ for security questionnaires and vulnerability reports.
ReadSignFlow · Product · Pricing · Security · Solutions · Resources · Enterprise · vs. e-signature · FAQ · Customers · About · Careers · For recipients · Status · Contact us · Start free · Sign in
Privacy · Terms · DPA · Acceptable use · Recipient terms · Cookies