Trust Center

Security you can explain to your customers.

E-signatures are only worth anything if they hold up. Here's exactly how QDigiSign keeps your documents private, proves they weren't altered, and meets the rules in the regions you operate in โ€” in plain English, no jargon.

How we protect your documents

๐Ÿ”’

Documents are encrypted when stored

Every uploaded and signed PDF is scrambled on our servers using AES-256 โ€” the same class of encryption banks use. A stolen file is useless without the key.

๐Ÿงพ

Tamper-proof fingerprint on every signed file

When signing completes, we take a unique fingerprint (SHA-256) of the document. If anyone changes even one character afterwards, the fingerprint no longer matches โ€” so tampering is instantly detectable.

๐Ÿ“œ

A full, unalterable activity trail

We record who uploaded, who opened, who signed, the exact time, the IP address, and the browser/device for every step โ€” kept as an audit trail that can't be quietly edited.

๐Ÿ‘ฅ

Role-based access

Admin, Manager, HR, Employee and Auditor roles come built in, and each workspace can create its own roles with precisely the permissions it wants. People only see what their role allows.

๐Ÿ“ฑ

Two-step login (MFA)

Users can add a one-time code from an authenticator app on top of their password, and a workspace can require it for everyone.

๐ŸŒ

Network & session controls

Restrict sign-in to trusted office networks (IP allowlist) and set how long a session lasts before re-login is required.

๐Ÿ›‚

Strong passwords, anti-brute-force

Passwords are stored using one-way bcrypt hashing (never as plain text), must meet a strength policy, and repeated bad attempts are rate-limited and logged.

๐Ÿ”

Encrypted connections

All traffic runs over HTTPS/TLS 1.2+ in production, with strict browser security headers that block common web attacks.

๐Ÿข

Your data stays separated

Every customer (tenant) is isolated. One organisation can never see another's documents, users or audit trail.

Built for the rules where you do business

QDigiSign is designed to support the privacy and e-signature laws of each region below. Per-workspace settings let you choose your data controls, currency and language.

๐Ÿ‡ฎ๐Ÿ‡ณ

India

Built to support the DPDP Act 2023 and the IT Act 2000 ยง5 basis for electronic signatures, with GST-compliant invoicing.

๐Ÿ‡ช๐Ÿ‡บ

European Union / UK

Designed around GDPR / UK-GDPR principles โ€” data-subject access, deletion, retention controls and eIDAS-style electronic-signature evidence.

๐Ÿ‡บ๐Ÿ‡ธ

United States

Supports the ESIGN Act and UETA legal basis for electronic signatures and records.

๐Ÿ‡จ๐Ÿ‡ฆ

Canada

Aligned with PIPEDA privacy principles and Canada's electronic-documents legislation (PIPEDA Part 2).

๐Ÿ‡ฟ๐Ÿ‡ฆ

South Africa

Built to support POPIA privacy requirements and ECTA electronic-signature recognition.

๐Ÿ‡ธ๐Ÿ‡ฆ

Saudi Arabia

Designed to support the PDPL (SDAIA) data-protection requirements and KSA e-transactions law.

Certifications & assurance

We believe in being straight about where we are. Here's the honest status โ€” what's live today versus what we're working toward.

Live

Encryption at rest & in transit

AES-256 storage encryption + HTTPS/TLS โ€” live today.

Live

Tamper-evident audit trail & document fingerprinting

Live today on every signed document.

Live

Role-based access, MFA, network & session controls

Live today, configurable per workspace.

In progress

SOC 2 Type II

Controls being implemented; independent audit planned. Report available under NDA once complete โ€” not yet certified.

In progress

Independent penetration testing

Third-party test scheduled; summary letter available to enterprise customers on request once complete.

In progress

Disaster recovery & vulnerability management

Documented processes with defined RTO/RPO targets; formal program maturing.

This page describes QDigiSign's security design and current posture. โ€œAlignedโ€ / โ€œbuilt to supportโ€ means the product is designed to help you meet that framework's requirements; it is not a statement of independent certification. For your specific legal/compliance obligations, please consult your advisors. Enterprise customers can request our security documentation pack.

Questions from your security team?

We're happy to walk through any of this. Start free and see the controls yourself, or reach out for the full documentation pack.