Acceptable use policy acknowledgement your auditor can actually verify.
ReadSignFlow tracks acceptable use policy acknowledgements and information security policy attestations across employees and contractors — with a read gate, signature, and timestamp on every sign-off, exported as a one-click audit pack for ISO 27001 and SOC 2 audits. Joiners are auto-assigned the AUP on day one via HRIS sync or API, and automatic reminders with manager escalation chase every unsigned policy to zero. Book an IT & security demo to see the workflow end to end.
From the AUP every joiner signs on day one to the security bulletin after a phishing wave, ReadSignFlow enforces a read gate, captures the signature, and hands you the evidence pack your ISO 27001 or SOC 2 auditor asks for — per person, per policy version, timestamped.
Policy attestation is a control. Most teams run it like a chore.
- 01 — The auditor asks for evidence — you have a spreadsheet. The PBC list says "evidence that all personnel acknowledged the information security policy." What exists is an intranet page, a stale tracker, and an email thread. Sampling three names shouldn't take three days of forensics.
- 02 — Access is provisioned before the AUP is signed. New joiners get laptops, VPN, and admin consoles on day one — and sign the acceptable use policy whenever HR gets around to it. That gap is exactly the kind of finding an ISO 27001 surveillance audit writes up.
- 03 — Contractors, BYOD, and v3 of every policy. Vendors and contractors have no corporate email. Policies get revised and nobody re-acknowledges the current version. Your attestation coverage quietly decays between audits, and no one owns chasing it.
Eight use cases, one platform.
Every attestation workflow your security, GRC, and IT ops teams need to evidence — without building it in ticketing or spreadsheets.
- AUP sign-off tracking — day one and every year — Joiners are auto-enrolled from your HRIS and sign the acceptable use policy before their first standup; an always-on annual campaign handles the re-acknowledgement — policy compliance software with reminders and manager escalation built in.
- ISO 27001 & SOC 2 policy attestation evidence — Turn your information security policy set into named, timestamped acknowledgements per person and per version — the evidence your auditor samples against Annex A 5.10 and 6.3, exported in one click.
- Incident response communications, acknowledged — When the IR plan changes or an incident postmortem lands, push it to responders and stakeholders with a read gate — so "everyone was briefed" is a report, not a hope.
- BYOD & remote access policy attestation — Distribute BYOD and remote-access agreements to exactly the people they cover using role and site segments, and capture a signature before the device or VPN grant goes live.
- Data classification & handling sign-off — Roll out classification and handling standards to data owners and handlers, with per-recipient deadlines and folder-level versioning so the current standard is always the one on record.
- Password & MFA standard rollouts — Ship a new passkey or MFA standard to privileged users first, then the wider workforce — tracking acknowledgement by segment so enforcement dates never surprise anyone.
- Security awareness attestation after phishing events — After a live phishing wave, send the bulletin over SMS and email with a tight deadline, watch acknowledgement climb in real time, and escalate the stragglers to their managers automatically.
- Vendor & contractor security terms — Magic-link delivery means third parties sign your security terms and NDAs on their own phones — no accounts, no app — and appear in the same coverage report as employees.
What security teams actually send through ReadSignFlow.
The AUP re-acks, urgent bulletins, and standard rollouts that need a verifiable signature from every employee, contractor, and privileged user.
Core security policies
- Acceptable use policy (AUP)
- Information security policy (ISMS scope)
- Access control & least-privilege policy
- Data classification & handling standard
Bulletins & incident comms
- Phishing & credential-theft alerts
- Incident response plan acknowledgements
- Emergency change & maintenance notices
- Post-incident lessons-learned briefs
People & third parties
- BYOD & remote access agreements
- Vendor & contractor security terms
- Privileged / admin account agreements
- Leaver data-return & access-revocation attestations
Built for the frameworks your evidence requests come from.
Attestation records, retention policies, and audit pack formats that map to the control frameworks and regulators your ISMS answers to.
Frameworks covered: ISO/IEC 27001:2022, SOC 2 (AICPA TSC), NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls v8, PCI DSS 4.0, GDPR (EU), UK GDPR & DPA 2018, NIS2 Directive (EU), DORA (EU), Cyber Essentials (UK), HIPAA Security Rule, GLBA / FTC Safeguards Rule, ISO/IEC 27701.
Frequently asked questions
Can ReadSignFlow track acceptable use policy acknowledgements for ISO 27001?
Yes — that's the core workflow. You publish the AUP, ReadSignFlow enforces a read gate before anyone can sign, and each acknowledgement is captured with signer identity, a UTC timestamp, and a tamper-evident event trail. That gives you named, dated evidence for Annex A controls like 5.10 (acceptable use) and 6.3 (awareness) instead of an intranet page nobody can prove was read. If you run wider governance software — a GRC or ISMS platform — the REST API and HMAC-signed webhooks push each acknowledgement event into it.
Can new joiners be assigned the AUP automatically before they get access?
Yes. JML auto-enrolment syncs joiners from your HRIS (or via REST API and CSV) into an always-on onboarding campaign, so the AUP and core security policies land on day one with a per-recipient deadline. When someone moves role or you publish a new policy version, you can trigger a re-acknowledgement of the current version — versioning is built in.
What evidence do we actually hand to a SOC 2 or ISO 27001 auditor?
A one-click audit pack: the signed PDF for each person (eIDAS and ESIGN/UETA-aligned signatures) plus an append-only event log showing delivery, open, read, and sign timestamps per recipient. When the auditor samples three names from your population, you export their records in the meeting rather than reconstructing screenshots and email threads afterwards.
How much effort is it to roll out security policy acknowledgement software to 500 people?
Launch takes days, not a project: upload the policy, sync or import people, target by department, site, or role using segments, set the deadline, and send. Automatic reminders at T-7, T-3, and T-24 hours plus manager escalation do the chasing. The Free tier covers up to 20 employees if you want to pilot with the IT team first; Enterprise adds SSO and EU/US data residency.
Can contractors and vendors without corporate email sign our security policies?
Yes. Recipients get a secure magic link over email, SMS, or WhatsApp — or scan a QR poster or use the recipient portal — and read and sign on their own phone with no account or app. Contractor and vendor security terms are tracked in the same dashboard as staff, so your third-party population stops being the blind spot in the attestation report.
Product · Pricing · Security · Solutions · Resources · Book a demo