Security & Compliance
Enterprise-grade security measures protecting your documents and data at every layer.
Security Architecture
AES-256 Encryption
All documents are encrypted at rest using AES-256, the same encryption standard used by banks and government agencies.
TLS 1.3 in Transit
Data transmitted between your browser and our servers is protected with TLS 1.3 encryption.
Document Integrity
SHA-256 hashing ensures documents cannot be tampered with after signing. Any modification invalidates the signature.
Audit Trails
Comprehensive logging of every action with timestamps, IP addresses, and actor information for full accountability.
Role-Based Access
Granular permission controls ensure team members only access documents and features appropriate to their role.
Secure Infrastructure
Infrastructure hosted on enterprise-grade cloud providers with 99.9% uptime SLA and redundant backups.
Document Lifecycle Security
Upload & Encryption
Documents are encrypted immediately upon upload using AES-256 before being stored.
Secure Token Generation
Unique, time-limited signing tokens are generated for each recipient with expiration controls.
TLS-Encrypted Delivery
Document access links are delivered via TLS 1.3 encrypted channels only.
Audit Logging
Every view, signature, and action is logged with IP address, timestamp, and device fingerprint.
Completion & Archival
Signed documents are hashed and stored with immutable audit trails for legal compliance.
Compliance Standards
SOC 2 Type II
Security, availability, and confidentiality controls audited by third-party assessors.
GDPR
Full compliance with EU data protection regulations including data portability and right to erasure.
HIPAA
Architecture designed to support HIPAA compliance for healthcare organizations with BAA available.
ESIGN Act
Electronic signatures legally binding under U.S. federal law with proper consent and authentication.
Incident Response
Security Incident Protocol
In the unlikely event of a security incident, our incident response team follows a structured protocol:
- Immediate containment and investigation within 1 hour of detection
- Affected customers notified within 24 hours with full transparency
- Root cause analysis and remediation plan within 72 hours
- Post-incident review and security improvements implemented
Report security concerns to: security@zenesign.com
Questions about our security practices?
We're happy to provide additional information about our security architecture.
Contact Security Team →