Touch2Sign/ Trust Center
Product securityPolicy libraryRequest access

Trust Center · Updated 21 August 2026

Security and compliance, in one place

Security, privacy, and compliance documentation for Touch2Sign — what is live today, and what is still in progress.

4 frameworks ready3 programmes in progress14 public documents
Browse resourcesBook a security review

Compliance

Honest status — we publish what is operational today and what is still on the certification path. We do not claim ISO 27001 or SOC 2 until reports exist.

GDPR / UK GDPR

Available

Operational privacy programme: DPA, ROPA, DPIA, DSAR and breach procedures.

Processor role for signing workflows under customer instruction; controller for accounts, billing, and platform security.

View details →

eIDAS & UK electronic signatures

Available

Product supports SES, AES, and QES via QTSP partners — eIDAS-aligned, not “eIDAS certified”.

QES via eID Easy; UK AES via OneID (DIATF Medium) with PAdES sealing. Customer selects the right signature level.

View details →

UK DIATF (via OneID)

Available

Bank-verified UK identity through OneID, certified under the UK Digital Identity and Attributes Trust Framework.

View details →

EU AI Act Art. 50

In progress

Transparency mapping for Aria / Sentinel published; counsel review of messaging still open.

View details →

ISO 27001:2022

In progress

ISMS policies, scope, risk register, and operating model in place. Certification audit not started.

Target: Stage 1 ~Month 10 of the compliance programme; certificate ~Month 18.

SOC 2 Type I / II

In progress

Control design and evidence logging underway. No SOC report available yet.

Target: Type I ~Month 9; Type II after observation period (~Month 18). Reports will be shared under NDA.

NIS2 / DORA (customer support)

Available

We help in-scope customers meet supplier due-diligence expectations; we do not claim entity certification under NIS2 or DORA.

View details →

HIPAA

Out of scope

Default out of scope — no PHI, no BAA unless expressly agreed in writing.

View details →

Security controls

Product and operational controls that prospects ask about in due diligence.

infrastructure

Encryption in transit (TLS)

HTTPS / TLS enforced for application and API traffic.

Available
infrastructure

Encryption at rest

AES-256 class encryption for stored documents and database volumes (AWS).

Available
product

Document integrity hashing

SHA-256 hashing and tamper-evident signed artifacts.

Available
product

Cryptographic PDF signatures (PAdES)

AES/QES flows embed signatures in the PDF — not audit-trail only.

Available
product

Audit trail & SCCR

Per-document event log, Signer Completion Certificate, and evidence pack export.

Available
product

Identity verification tiers

Email/SMS OTP, OneID (UK DIATF), eID Easy national eID / QES.

Available
product

Admin MFA

TOTP required for organisation admins and platform staff consoles.

Available
privacy

DSAR tooling

Org-level DSAR register, 30-day SLA tracking, and export packs.

Available
privacy

Retention & legal hold

Configurable retention, pre-purge notices, per-document legal hold.

Available
infrastructure

EU data residency (primary)

Primary hosting on AWS eu-west-1 (Ireland) with published sub-processors.

Available
privacy

Breach notification procedure

GDPR Art 33–34 playbook targeting 72-hour supervisory authority notice where required.

Available
operations

Change management

Release checklist and production change log for SOC 2 CC8-style evidence.

Available
operations

Access reviews

Quarterly access review log established.

Available
operations

Incident response tabletop

IR plan drafted; first tabletop exercise in progress.

In progress
operations

Backup / DR restore drill

BCP documented; first RDS restore drill scheduled.

In progress
operations

External penetration test

Annual external pentest planned; report will be available under NDA.

Planned
operations

Vendor SOC / ISO collection

Collecting current SOC 2 / ISO reports from key sub-processors.

In progress

Resources

Public policies and legal docs are linked below. Certification reports will be shared under NDA when available.

Privacy Policy

AvailablePublic

How we collect and use personal data.

Open →

Terms & Conditions

AvailablePublic

Customer terms, acceptable use, and eIDAS disclaimers.

Open →

Data Processing Agreement

AvailablePublic

GDPR Art 28 processor terms for signing workflows.

Open →

Pricing & Commercial Terms

AvailablePublic

Plans, meters, prepaid credits, billing.

Open →

Refund Policy

AvailablePublic

Standalone refund rules — seven-day unused window and chargebacks.

Open →

Cookie Policy

AvailablePublic

Cookies, analytics, and consent.

Open →

Minimum Compliance Pack

AvailablePublic

GDPR / privacy / eIDAS baseline checklist.

Open →

Record of Processing Activities (ROPA)

AvailablePublic

Art 30 processing records (controller + processor).

Open →

Platform DPIA

AvailablePublic

High-risk processing assessment — IDV, eWitness, AI.

Open →

eIDAS Compliance Guide

AvailablePublic

SES / AES / QES guidance for customers and teams.

Open →

EU AI Act Art. 50 Transparency Guide

AvailablePublic

How Aria and Sentinel meet transparency duties.

Open →

Information Security Policy

AvailablePublic

Master ISMS policy — objectives, roles, principles.

Open →

Full Policy Library

AvailablePublic

Security, privacy, engineering, and people policies.

Open →

Sub-processor register

AvailablePublic

Vendors that process customer data on our behalf.

Open →

SOC 2 Type II report

PlannedNDA

Will be available to qualified prospects under NDA once issued.

Request under NDA

ISO 27001 certificate

In progressNDA

Certification programme in progress — certificate not yet issued.

Request under NDA

Penetration test summary

PlannedNDA

External pentest report summary under NDA after first engagement.

Request under NDA

Security questionnaire / CAIQ

AvailableOn request

Enterprise due-diligence pack — request from security.

Request access

Subprocessors

Key vendors that process customer data. Full register and notification rules are in the DPA.

SubprocessorPurposeRegion
Amazon Web ServicesHosting, storage, email, auth, monitoringEU (Ireland) eu-west-1
OneID LimitedUK bank identity verification (AES)United Kingdom
eID Easy / DokobitQES signing & EU national eIDEU
NMIPreferred SaaS payment railUS (card vault at processor)
StripeAlternate payment processingUS / EU
AnthropicOptional document Q&A (Aria)USA (SCCs)
AWS SNSSMS OTP and alertsEU

Changes are notified per DPA (typically 30 days). Questions: legal@touch2sign.com

Certification roadmap

From the 18-month SOC 2 / ISO programme — public milestone view.

Policies v1.0 + ISMS scope
Target: Jul 2026
Done
Customer legal pack (Privacy, Terms, DPA, Refunds)
Target: Aug 2026
Done
ROPA + DPIA published
Target: Aug 2026
Done
IR tabletop exercise
Target: Q3 2026
In progress
RDS restore drill
Target: Q3 2026
Pending
External penetration test
Target: Month 5
Pending
SOC 2 Type I
Target: Month 9
Pending
ISO 27001 Stage 1
Target: Month 10
Pending
SOC 2 Type II + ISO certificate
Target: Month 18
Pending

Deeper programme docs (internal): Compliance Programme Hub · Product security deep-dive

Questions for security or procurement?

We can walk through architecture, data flows, sub-processors, and the certification roadmap. Request questionnaires or NDA documents from the security mailbox.