Version 1.0 · Draft · Owner: Security Lead
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Security Lead
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Define how Touch2Sign Ltd controls access to information systems, customer data, and administrative functions. This policy ensures that only authorised individuals receive the minimum access required to perform their role, in support of GDPR, ISO 27001, and SOC 2 requirements.
Applies to:
| Event | Actions | Owner | Target | Joiner | Create Cognito / AWS IAM account with role template; MFA enrolled before production access | Engineering Lead | Day 1 |
|---|---|---|---|
| Mover | Review and adjust permissions within 5 business days of role change | Security Lead | 5 days |
| Leaver | Disable Cognito user; revoke AWS IAM keys; remove GitHub access; rotate shared secrets if exposed | Engineering Lead | Same day |
All JML actions are logged in the access change register.
main / production branches — PR review required MFA is mandatory for:
| System | MFA method | Exceptions | AWS console and IAM users | TOTP or hardware key | None for production |
|---|---|---|
| GitHub organisation (admin/write) | TOTP or passkey | None |
| Touch2Sign admin / internal Cognito accounts | TOTP, SMS (where supported), or WebAuthn | None |
| Customer Cognito accounts | Recommended; enforced per org policy where product supports | Document in customer settings |
MFA bypass is not permitted except via documented break-glass procedure (Section 8).
Signing links use time-limited, cryptographically random tokens stored in the recipients table.
| Control | Requirement | Token generation | Cryptographically secure random; sufficient entropy |
|---|---|
| Expiry | Configured per document / org settings; expired tokens rejected |
| Single-use | Where product enforces one-time access for sensitive flows |
| Invalidation | On document void, completion, or suspected compromise — see Incident Response Plan §7.1 |
| Scope | Token grants access only to the linked document and signing actions — not admin or other tenants |
Support staff must not access signing URLs on behalf of customers unless explicitly authorised and logged.
The Security Lead conducts quarterly access reviews covering:
| Review field | Description | Account ID | Username / ARN |
|---|---|
| Role / purpose | Job function justification |
| Last login | From CloudTrail / Cognito logs |
| MFA enabled | Y/N |
| Still required? | Approver sign-off |
| Action | Retain / modify / revoke |
Reviews are documented in the access review spreadsheet; anomalies remediated within 10 business days.
Privileged access includes: AWS administrator, RDS superuser, production Secrets Manager write, Cognito admin API, and emergency production deploy rights.
For emergencies when normal MFA or access paths are unavailable (e.g. identity provider outage):
Suspected unauthorised access, credential sharing, or privilege abuse must be reported immediately to security@touch2sign.com. Follow the Incident Response Plan for containment.
This policy is reviewed annually or after a significant access-related incident.
Approval
| Name | Role | Signature | Date | Robert | CEO / Security Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com