Security, traceability and honest disclosure of technical evidence are at the heart of SignCloud.
All communications are encrypted in transit (HTTPS/TLS). Signing pages are only accessible via a non-guessable random token link.
Each signature is confirmed by a one-time code sent by SMS. The code is never stored in clear text and no email fallback is accepted for signing. A company registration check may be required by the sender.
A SHA-256 fingerprint is recorded for the signed PDF. Comparing a file with that fingerprint can reveal a later change. A technical evidence record (server time, IP address, verification channel and fingerprint) is available.
Every event (sending, opening, verification, signature, sealing) is recorded in a cryptographically chained audit trail: any later tampering is detectable.
SignCloud records the controls applied to each electronic-signature flow. Advanced and qualified eIDAS levels are not claimed unless their legal and technical prerequisites are operational and validated. Personal-data compliance and hosting commitments must be assessed against the production configuration and applicable contracts.
The production operator must document the actual hosting and backup locations and verify restorations. Access to workspaces is isolated per organization; passwords are stored hashed; two-factor authentication is available (authenticator app for admins, email code for clients). Sensitive actions are logged.
To report a vulnerability: securite@signcloud.fr.