Your documents are yours. Here’s how we treat them.
A plain summary of how VXSign handles data and security. For the formal documents, see the Privacy Policy and Data Processing Addendum.
Data ownership
Your documents, signer information, and audit records belong to you. Access is scoped through API keys, and you can export or delete your data.
Encryption
Data is encrypted in transit (TLS) and at rest. Signing links and API keys are treated as secrets and never indexed.
Subprocessors
We use a small set of vetted subprocessors — a payment processor (Stripe), email delivery, and cloud hosting. The current list is maintained in the DPA.
Retention
Completed documents and their Certificates of Completion are retained for as long as your account needs them; deletion requests are honored.
Incident response
We monitor for security events and will notify affected customers of a confirmed breach without undue delay, per the DPA.
Standards
Operated with SOC 2-aligned controls and built to support ESIGN, UETA, and eIDAS. See Security for the cryptographic details.