SignITLog inRequest access

Security & trust

Designed so the safe path is the only path.

SignIT handles agreements and identities, so isolation and least privilege are structural, not optional.

Core guarantees

  • Tenant isolation. Every operation is scoped to one organization; data is never merged across organizations.
  • Authenticated intake. Inbound email is HMAC-signed at the edge and verified — signature, replay window, and body digest — before it is trusted.
  • Review-gated actions. Sending for signature, voiding, or changing signers requires an explicit, re-authorized approval.
  • Invite-only access. There is no self-service signup; unknown identities are rejected at login.
  • Capability-scoped signing. Signing links carry short-lived tokens that authorize exactly one signer.
  • Least data by default. Team notifications about agreements are metadata-only — never message bodies, attachments, or tokens.

Known limitations

SignIT is an early private-alpha. We describe our controls honestly and we do not overstate them.

  • SignIT is not a certified, independently audited, or legally reviewed e-signature service, and makes no claim of eIDAS/QES, ESIGN/UETA, SOC 2, or other compliance certification.
  • Email routing and verified sending are being set up; until then, agreement email delivery is limited and sender addresses are not yet operational.
  • The service is under active development; interfaces and data may change during the alpha, and availability is not guaranteed.
  • Legal enforceability of an electronic signature depends on your jurisdiction and circumstances — SignIT provides the technical record, not legal advice.

Report a vulnerability or abuse

We welcome coordinated disclosure. Use the contact form (choose "Security / abuse") with details and reproduction steps — a dedicated security address will be published here once our email routing is verified. Please do not test against other organizations' data.