Touch2Sign

Compliance & Policy Library

ISO 27001 · SOC 2 · GDPR · eIDAS — internal policies and customer-facing legal documents.

Status: Policies v1.0 approved 11 July 2026. ISO 27001 / SOC 2 certification programmes in progress. Open Compliance Programme Hub →
Compliance Programme Hub
Processes, checklists, evidence logs, roadmap milestones, and Argus service status.
Minimum Compliance Pack — start here
GDPR, privacy, and eIDAS baseline — ROPA, DPIA, customer-facing legal docs, and quarterly checklist.

Security & ISMS

Information Security Policy
Master ISMS policy — objectives, roles, and security principles.
Approved 1.0
Owner: Robert — Security Lead
Risk Management Policy
Risk assessment methodology, register, and treatment.
Draft 1.0
Owner: Security Lead
Incident Response Plan
Detection, containment, GDPR 72h breach notification, recovery.
Draft 1.0
Owner: Security Lead
Access Control Policy
Least privilege, MFA, joiner-mover-leaver, quarterly reviews.
Draft 1.0
Owner: Security Lead
Acceptable Use Policy
Permitted use of Touch2Sign systems, data, and equipment.
Draft 1.0
Owner: Security Lead
Password & Authentication Standard
Cognito passwords, MFA, signing tokens, WebAuthn.
Draft 1.0
Owner: Security Lead
Data Classification & Handling
Public, internal, confidential, and restricted data handling.
Draft 1.0
Owner: Security Lead

Privacy & GDPR

Record of Processing Activities (ROPA)
GDPR Art 30 — controller and processor processing records.
Approved 1.0
Owner: Privacy Lead
Data Protection Impact Assessment (DPIA)
High-risk processing assessment — IDV, eWitness, AI.
Approved 1.0
Owner: Privacy Lead
Legitimate Interest Assessment — Security Logs
Lawful basis for security and audit logging (Art 6(1)(f)).
Approved 1.0
Owner: Privacy Lead
Vendor & Sub-processor Management
Third-party risk, DPAs, SOC reports, sub-processor register.
Draft 1.0
Owner: Legal + Security
Data Retention & Disposal
Retention periods, secure deletion, eIDAS evidence.
Draft 1.0
Owner: DPO
Breach Notification Procedure
GDPR Art 33–34 — ICO/DPC 72h, customer notification.
Draft 1.0
Owner: DPO
Data Subject Access Request Procedure
DSAR intake, 30-day SLA, controller vs processor.
Draft 1.0
Owner: DPO
Cookie Policy
Cookies, analytics, and consent (ePrivacy).
Draft 1.0
Owner: Legal

Engineering & Operations

Vulnerability Management Policy
Scanning, patch SLAs, pentest, and exception tracking.
Draft 1.0
Owner: Engineering Lead
Secure Development Policy
SDLC, code review, secrets, dependency approval.
Draft 1.0
Owner: Engineering Lead
Change Management Policy
Production changes, emergency fixes, deployment controls.
Draft 1.0
Owner: Engineering Lead
Cryptography & Key Management
TLS, encryption at rest, Secrets Manager, key rotation.
Draft 1.0
Owner: Engineering Lead
Business Continuity & DR Plan
Backup, restore, RTO/RPO, AWS failover.
Draft 1.0
Owner: Engineering Lead

HR & People

Remote Working Policy
Secure remote access, device requirements, clean desk.
Draft 1.0
Owner: HR
Security Awareness Training
Induction, annual training, phishing, incident reporting.
Draft 1.0
Owner: HR

Legal & Customer

Minimum Compliance Pack
Start here — GDPR, privacy, and eIDAS baseline checklist.
Approved 1.0
Owner: Privacy Lead
eIDAS Compliance Guide
SES, AES, QES — customer and team guidance for eIDAS alignment.
Approved 1.0
Owner: Legal
EU AI Act Article 50 — Transparency Guide
How Aria and Sentinel meet AI Act transparency duties; customer deployer checklist.
Approved 1.0
Owner: Legal
HIPAA Scope Decision (Out of Scope)
Default position — no PHI, no BAA unless explicitly agreed.
Draft 1.0
Owner: Legal
Privacy Policy
Public privacy policy for data subjects.
Live
Owner: Legal
Data Processing Agreement
GDPR Art 28 processor terms for customers.
Live
Owner: Legal
Terms of Service
Customer terms, acceptable use, eIDAS disclaimers.
Live
Owner: Legal
Pricing & Commercial Terms
Plans, meters, prepaid AES/QES credits (12-month expiry), Legal pack, billing and refunds.
Live
Owner: Legal
Refund Policy
Standalone refund rules: seven-day unused window, processing fee, chargebacks.
Live
Owner: Legal

See also: Trust Center · Product security · DPA · security@touch2sign.com