Acceptable use policy acknowledgement your auditor can actually verify.

ReadSignFlow tracks acceptable use policy acknowledgements and information security policy attestations across employees and contractors — with a read gate, signature, and timestamp on every sign-off, exported as a one-click audit pack for ISO 27001 and SOC 2 audits. Joiners are auto-assigned the AUP on day one via HRIS sync or API, and automatic reminders with manager escalation chase every unsigned policy to zero. Book an IT & security demo to see the workflow end to end.

From the AUP every joiner signs on day one to the security bulletin after a phishing wave, ReadSignFlow enforces a read gate, captures the signature, and hands you the evidence pack your ISO 27001 or SOC 2 auditor asks for — per person, per policy version, timestamped.

Policy attestation is a control. Most teams run it like a chore.

Eight use cases, one platform.

Every attestation workflow your security, GRC, and IT ops teams need to evidence — without building it in ticketing or spreadsheets.

What security teams actually send through ReadSignFlow.

The AUP re-acks, urgent bulletins, and standard rollouts that need a verifiable signature from every employee, contractor, and privileged user.

Core security policies

Bulletins & incident comms

People & third parties

Built for the frameworks your evidence requests come from.

Attestation records, retention policies, and audit pack formats that map to the control frameworks and regulators your ISMS answers to.

Frameworks covered: ISO/IEC 27001:2022, SOC 2 (AICPA TSC), NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls v8, PCI DSS 4.0, GDPR (EU), UK GDPR & DPA 2018, NIS2 Directive (EU), DORA (EU), Cyber Essentials (UK), HIPAA Security Rule, GLBA / FTC Safeguards Rule, ISO/IEC 27701.

Frequently asked questions

Can ReadSignFlow track acceptable use policy acknowledgements for ISO 27001?

Yes — that's the core workflow. You publish the AUP, ReadSignFlow enforces a read gate before anyone can sign, and each acknowledgement is captured with signer identity, a UTC timestamp, and a tamper-evident event trail. That gives you named, dated evidence for Annex A controls like 5.10 (acceptable use) and 6.3 (awareness) instead of an intranet page nobody can prove was read. If you run wider governance software — a GRC or ISMS platform — the REST API and HMAC-signed webhooks push each acknowledgement event into it.

Can new joiners be assigned the AUP automatically before they get access?

Yes. JML auto-enrolment syncs joiners from your HRIS (or via REST API and CSV) into an always-on onboarding campaign, so the AUP and core security policies land on day one with a per-recipient deadline. When someone moves role or you publish a new policy version, you can trigger a re-acknowledgement of the current version — versioning is built in.

What evidence do we actually hand to a SOC 2 or ISO 27001 auditor?

A one-click audit pack: the signed PDF for each person (eIDAS and ESIGN/UETA-aligned signatures) plus an append-only event log showing delivery, open, read, and sign timestamps per recipient. When the auditor samples three names from your population, you export their records in the meeting rather than reconstructing screenshots and email threads afterwards.

How much effort is it to roll out security policy acknowledgement software to 500 people?

Launch takes days, not a project: upload the policy, sync or import people, target by department, site, or role using segments, set the deadline, and send. Automatic reminders at T-7, T-3, and T-24 hours plus manager escalation do the chasing. The Free tier covers up to 20 employees if you want to pilot with the IT team first; Enterprise adds SSO and EU/US data residency.

Can contractors and vendors without corporate email sign our security policies?

Yes. Recipients get a secure magic link over email, SMS, or WhatsApp — or scan a QR poster or use the recipient portal — and read and sign on their own phone with no account or app. Contractor and vendor security terms are tracked in the same dashboard as staff, so your third-party population stops being the blind spot in the attestation report.

Product · Pricing · Security · Solutions · Resources · Book a demo

ReadSignFlow on LinkedIn, YouTube, Instagram, and Facebook.