Back to Home

Security You Can Verify

SignaTrust is built on transparency. Every security claim is backed by independent audits, certifications, and blockchain- verifiable proof.

SOC 2 Type II In ProgressBlockchain Verified

Retention in one sentence: SignaTrust holds the signed document for up to 7 days (or zero days with BYOS), then deletes its copy — the blockchain anchor and your storage provider keep the only persistent records.

Certifications & Compliance

Our security posture is validated by independent auditors and regulatory frameworks.

In Progress

SOC 2 Type II

Security controls implemented for data protection, availability, and confidentiality. Type II audit in progress with Thoropass; Type I report expected Q3 2026.

Q2 2026

ISO 27001

International standard for information security management systems.

Partial

GDPR

Implementing GDPR data protection practices. Full compliance features including data export and deletion requests are on our roadmap.

Compliant

CCPA

California Consumer Privacy Act compliance for US customer data rights.

Compliant

ESIGN/UETA

Legal compliance with US electronic signature laws for binding agreements.

SES + RFC 3161

eIDAS (EU)

Simple Electronic Signatures (SES) tier under EU Regulation 910/2014, paired with RFC 3161 trusted timestamping. Advanced (AES) and Qualified (QES) tiers are on our roadmap; we do not claim them today.

Business plan

HIPAA

Business Associate Agreement (BAA) signed via SignaTrust's own envelope flow on the Business plan. Implements §164.312 technical safeguards (access control, audit controls, integrity, transmission security). PHI is never written to our blockchain anchor — only document hashes.

Active

Blockchain Verified

Every signed document is anchored to Solana blockchain for immutable proof.

Independently Verifiable

Unlike traditional e-signature platforms, SignaTrust anchors document hashes to the Solana blockchain. Anyone can verify document integrity without trusting us - the proof exists on a public, decentralized ledger.

Security Architecture

Defense-in-depth approach with multiple layers of protection.

Encryption at Rest & Transit

All data encrypted with AES-256 at rest and TLS 1.3 in transit.

Blockchain Anchoring

Document hashes anchored to Solana blockchain for tamper-proof verification.

Comprehensive Audit Logs

Every action logged with timestamp, IP address, and user context.

Role-Based Access Control

Granular permissions ensure users only access what they need.

Compliance Guides

Download our guides to understand how SignaTrust's zero-custody architecture addresses your regulatory requirements.

Zero-Custody Architecture

Enterprise whitepaper covering HIPAA, GDPR, SOC 2, ESIGN, CCPA, FINRA, and SEC compliance.

Enterprise

HIPAA Compliance Guide

Why zero-custody architecture matters more than a BAA for protecting PHI.

Healthcare

FINRA/SEC Compliance Guide

Record ownership, retention, and blockchain verification for financial services.

Financial Services

Data Processing

Transparency about where your data lives and who processes it.

Infrastructure

Primary RegionAWS us-east-1 (N. Virginia)
DatabasePostgreSQL (encrypted)
Document StorageAWS S3 (AES-256)
Data Retention7 years (configurable)
BYOS RetentionZero days — buffer purged after delivery

When customers bring their own storage (BYOS), the SignaTrust buffer holds the signed document only until all parties confirm receipt — typically minutes to hours, never days. Your storage provider is the only persistent copy. How buffer purge works.

Subprocessors

Amazon Web Services (AWS)

Infrastructure, document storage, database hosting

US (us-east-1)

Vercel

Application hosting and edge network

US (Global CDN)

Stripe

Payment processing

US

Twilio

SMS notifications for signers

US

Solana Network

Blockchain anchoring for document verification

Decentralized

Sentry

Error monitoring and performance tracking

US

Request Compliance Documents

Access our security documentation for your vendor assessment.

SOC 2 Type II Report

Full audit report (NDA required)

Penetration Test Summary

Latest security assessment results

Security Questionnaire

Pre-filled SIG/CAIQ responses

Contact our security team to request documentation.

Email our security team

security@signatrust.io

System Status

Real-time availability and incident history

View Status Page