Agreements often contain sensitive business and personal information. eSigner is designed with layered safeguards for the documents entrusted to the platform. This page describes our current approach without claiming certifications we have not earned.
Infrastructure and isolation
eSigner runs on Amazon Web Services in a production environment separated from development. Application services, databases, document storage, and secrets are isolated by environment and protected through network access controls.
Encryption
Traffic to the eSigner application is protected using HTTPS. Production database and object storage use encryption at rest. Application secrets and signing material are stored separately from source code and delivered to authorized workloads at runtime.
Access and application controls
- Authenticated workspaces and role-based team access.
- Recipient-specific signing workflows and transaction records.
- Managed web application firewall rules for common attacks and abusive traffic.
- Restricted service-to-service and database network access.
- Public registration disabled during controlled production onboarding.
Resilience and recovery
Production runs across multiple availability zones. Database backups, protected object versions, health checks, and service monitoring support recovery from operational failures. No service can promise uninterrupted availability, but we design operations to detect problems and restore service responsibly.
Monitoring and email reputation
Application and infrastructure health are monitored with centralized logs and alerts. Transactional email delivery, bounces, and complaints are monitored, and suppressed recipients are not treated as ordinary delivery targets.
Customer responsibilities
Security is shared. Customers should use unique credentials, limit team access, verify recipient addresses, protect downloaded files, and promptly cancel requests sent to the wrong person. Never share a signing link publicly.
Report a vulnerability
Please report suspected security vulnerabilities privately to security@esigner.ai. Include a clear description, affected URL or feature, reproduction steps, and potential impact. Do not access data that is not yours, disrupt service, or publicly disclose an unresolved issue. We will acknowledge good-faith reports and work to validate and remediate confirmed findings.
Security questions
For security questionnaires or architecture questions, contact security@esigner.ai.