Security

Trust isn't a feature. It's the foundation.

Sealsimple is built so that every document, every signature, and every audit event can be verified — by you, your counterparty, or a court.

Encryption in transit & at rest

TLS 1.2+ for every request. Documents and signatures are encrypted at rest in a private storage bucket and served only through short-lived signed URLs.

Tamper-evident audit trail

Every send, view, sign, and decline event is recorded with IP, timestamp, and user-agent. The final PDF is fingerprinted with SHA-256 so any later change is detectable.

Certificate of completion

Each finalised document includes a certificate listing every signer, every event, and the SHA-256 hash of the final PDF.

Row-level access control

Postgres row-level security ensures senders see only their own documents and signers reach a document only via their tokenised link.

Resilient infrastructure

Hosted on a managed cloud platform with automated backups, point-in-time recovery, and 24/7 monitoring.

Legally binding

Signatures comply with the U.S. ESIGN Act, UETA, and the EU eIDAS Regulation. Signers consent to electronic signing before their first signature.

Questions about our security posture? Email security@sealsimple.com.