Built to the standard auditors expect.

SOC 2 Type II and ISO 27001 controls (certification in progress), GDPR-aligned, EU and US data regions, SSO/SAML, encryption in transit and at rest, and eIDAS and US ESIGN/UETA signatures. The append-only, tamper-evident audit log is audit trail software in the strict sense: every acknowledgement event is recorded immutably and exported as audit-ready documentation on demand.

Security questions

Is ReadSignFlow SOC 2 and ISO 27001 certified?

We operate to SOC 2 Type II and ISO 27001 controls; formal certification is in progress. A control summary, and SOC 2 / penetration-test reports under NDA, are available to enterprise customers on request.

What encryption does ReadSignFlow use?

Data is encrypted in transit with TLS and at rest with AES-256, with strict per-tenant isolation at the database layer.

Where is my data stored?

Hosted in EU and US data regions. Cross-border transfers, where they occur, are covered by Standard Contractual Clauses and the UK Addendum.

Do you support SSO and MFA?

Yes — SSO via SAML 2.0 (Microsoft Entra, Google, and other IdPs) and multi-factor authentication, with SCIM provisioning on Enterprise.

Is the audit log tamper-evident?

Yes. The audit log is append-only and exported with a tamper-evident manifest, so every acknowledgement event can be independently verified.

Can I get a DPA and sub-processor list?

Yes. A Data Processing Agreement is available, and the current sub-processor list is available on request.

Product · Pricing · Security · Solutions · Resources · Book a demo

ReadSignFlow on LinkedIn, YouTube, Instagram, and Facebook.