Skip to content

Trust center

Security at eSigner

Practical safeguards for documents, signing workflows, and service availability.

Agreements often contain sensitive business and personal information. eSigner is designed with layered safeguards for the documents entrusted to the platform. This page describes our current approach without claiming certifications we have not earned.

Infrastructure and isolation

eSigner runs on Amazon Web Services in a production environment separated from development. Application services, databases, document storage, and secrets are isolated by environment and protected through network access controls.

Encryption

Traffic to the eSigner application is protected using HTTPS. Production database and object storage use encryption at rest. Application secrets and signing material are stored separately from source code and delivered to authorized workloads at runtime.

Access and application controls

  • Authenticated workspaces and role-based team access.
  • Recipient-specific signing workflows and transaction records.
  • Managed web application firewall rules for common attacks and abusive traffic.
  • Restricted service-to-service and database network access.
  • Public registration disabled during controlled production onboarding.

Resilience and recovery

Production runs across multiple availability zones. Database backups, protected object versions, health checks, and service monitoring support recovery from operational failures. No service can promise uninterrupted availability, but we design operations to detect problems and restore service responsibly.

Monitoring and email reputation

Application and infrastructure health are monitored with centralized logs and alerts. Transactional email delivery, bounces, and complaints are monitored, and suppressed recipients are not treated as ordinary delivery targets.

Customer responsibilities

Security is shared. Customers should use unique credentials, limit team access, verify recipient addresses, protect downloaded files, and promptly cancel requests sent to the wrong person. Never share a signing link publicly.

Report a vulnerability

Please report suspected security vulnerabilities privately to security@esigner.ai. Include a clear description, affected URL or feature, reproduction steps, and potential impact. Do not access data that is not yours, disrupt service, or publicly disclose an unresolved issue. We will acknowledge good-faith reports and work to validate and remediate confirmed findings.

Security questions

For security questionnaires or architecture questions, contact security@esigner.ai.