Version 1.0 · Draft · Owner: Engineering Lead
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Engineering Lead
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Define how Touch2Sign identifies, prioritises, remediates, and tracks security vulnerabilities in application code, dependencies, and cloud infrastructure. Supports ISO 27001 A.8.8 and SOC 2 CC7.1.
Covers:
| Source | Frequency | Owner | GitHub Dependabot | Continuous | Engineering |
|---|---|---|
| npm audit | Weekly in CI | Engineering |
| AWS Inspector / Security Hub | Continuous (when enabled) | Engineering |
| Manual code review | Per PR | Engineering |
| Penetration test | Annual minimum | Security Lead |
| Customer / researcher reports | Ad hoc | security@touch2sign.com |
| CVE monitoring | Continuous | Security Lead |
Align with CVSS v3.1 where applicable:
| Severity | CVSS range | Examples | Critical | 9.0 – 10.0 | RCE in production, auth bypass, exposed DB, active exploitation |
|---|---|---|
| High | 7.0 – 8.9 | SQLi with constraints, privilege escalation, sensitive data leak path |
| Medium | 4.0 – 6.9 | XSS stored, CSRF on sensitive action, outdated lib with known exploit chain |
| Low | 0.1 – 3.9 | Information disclosure minimal impact, hardening opportunities |
| Informational | N/A | Best practice; no SLA |
Touch2Sign may escalate severity based on exploitability in our environment (e.g. signing token exposure = Critical).
| Severity | Remediation target | Escalation if missed | Critical | 7 calendar days | CEO + daily IC standup |
|---|---|---|
| High | 30 calendar days | Security Lead weekly review |
| Medium | 90 calendar days | Sprint backlog |
| Low | Next maintenance window | No escalation |
| Informational | Best effort | — |
SLAs start from confirmed triage date, not original discovery date.
For actively exploited Critical vulnerabilities:
For each finding, record:
| Field | Description | ID | VULN-YYYY-NNN |
|---|---|
| Source | Dependabot / pentest / etc. |
| Affected component | Package, service, endpoint |
| Severity | Critical / High / Medium / Low |
| Exploitability | Public exploit Y/N |
| Customer data at risk? | Y/N |
| Owner | Named engineer |
| Due date | Per SLA |
| Status | Open / In progress / Mitigated / Closed / Accepted |
If SLA cannot be met:
| Requirement | Detail | Frequency | At least annually; after major architecture change |
|---|---|
| Scope | Production-like environment; signing flows; admin routes; API |
| Provider | Independent third party; NDA and rules of engagement |
| Retest | Critical/High findings retested after remediation |
| Report retention | 3 years minimum |
First pentest target: Month 9 of compliance programme.
External researchers may report vulnerabilities to security@touch2sign.com. Touch2Sign will:
Reported to Security Lead monthly:
Reviewed annually and after significant vulnerability-related incidents.
Approval
| Name | Role | Signature | Date | Robert | CEO / Engineering Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com