Trust center

Your documents are yours. Here’s how we treat them.

A plain summary of how VXSign handles data and security. For the formal documents, see the Privacy Policy and Data Processing Addendum.

Data ownership

Your documents, signer information, and audit records belong to you. Access is scoped through API keys, and you can export or delete your data.

Encryption

Data is encrypted in transit (TLS) and at rest. Signing links and API keys are treated as secrets and never indexed.

Subprocessors

We use a small set of vetted subprocessors — a payment processor (Stripe), email delivery, and cloud hosting. The current list is maintained in the DPA.

Retention

Completed documents and their Certificates of Completion are retained for as long as your account needs them; deletion requests are honored.

Incident response

We monitor for security events and will notify affected customers of a confirmed breach without undue delay, per the DPA.

Standards

Operated with SOC 2-aligned controls and built to support ESIGN, UETA, and eIDAS. See Security for the cryptographic details.

This page is general information, not legal advice or a contract. The binding terms are in the Terms, Privacy Policy, and Data Processing Addendum.