GDPR / UK GDPR
AvailableOperational privacy programme: DPA, ROPA, DPIA, DSAR and breach procedures.
Processor role for signing workflows under customer instruction; controller for accounts, billing, and platform security.
View details →Trust Center · Updated 21 August 2026
Security, privacy, and compliance documentation for Touch2Sign — what is live today, and what is still in progress.
Honest status — we publish what is operational today and what is still on the certification path. We do not claim ISO 27001 or SOC 2 until reports exist.
Operational privacy programme: DPA, ROPA, DPIA, DSAR and breach procedures.
Processor role for signing workflows under customer instruction; controller for accounts, billing, and platform security.
View details →Product supports SES, AES, and QES via QTSP partners — eIDAS-aligned, not “eIDAS certified”.
QES via eID Easy; UK AES via OneID (DIATF Medium) with PAdES sealing. Customer selects the right signature level.
View details →Bank-verified UK identity through OneID, certified under the UK Digital Identity and Attributes Trust Framework.
View details →Transparency mapping for Aria / Sentinel published; counsel review of messaging still open.
View details →ISMS policies, scope, risk register, and operating model in place. Certification audit not started.
Target: Stage 1 ~Month 10 of the compliance programme; certificate ~Month 18.
Control design and evidence logging underway. No SOC report available yet.
Target: Type I ~Month 9; Type II after observation period (~Month 18). Reports will be shared under NDA.
We help in-scope customers meet supplier due-diligence expectations; we do not claim entity certification under NIS2 or DORA.
View details →Default out of scope — no PHI, no BAA unless expressly agreed in writing.
View details →Product and operational controls that prospects ask about in due diligence.
HTTPS / TLS enforced for application and API traffic.
AES-256 class encryption for stored documents and database volumes (AWS).
SHA-256 hashing and tamper-evident signed artifacts.
AES/QES flows embed signatures in the PDF — not audit-trail only.
Per-document event log, Signer Completion Certificate, and evidence pack export.
Email/SMS OTP, OneID (UK DIATF), eID Easy national eID / QES.
TOTP required for organisation admins and platform staff consoles.
Org-level DSAR register, 30-day SLA tracking, and export packs.
Configurable retention, pre-purge notices, per-document legal hold.
Primary hosting on AWS eu-west-1 (Ireland) with published sub-processors.
GDPR Art 33–34 playbook targeting 72-hour supervisory authority notice where required.
Release checklist and production change log for SOC 2 CC8-style evidence.
Quarterly access review log established.
IR plan drafted; first tabletop exercise in progress.
BCP documented; first RDS restore drill scheduled.
Annual external pentest planned; report will be available under NDA.
Collecting current SOC 2 / ISO reports from key sub-processors.
Public policies and legal docs are linked below. Certification reports will be shared under NDA when available.
How we collect and use personal data.
Customer terms, acceptable use, and eIDAS disclaimers.
GDPR Art 28 processor terms for signing workflows.
Plans, meters, prepaid credits, billing.
Standalone refund rules — seven-day unused window and chargebacks.
Cookies, analytics, and consent.
GDPR / privacy / eIDAS baseline checklist.
Art 30 processing records (controller + processor).
High-risk processing assessment — IDV, eWitness, AI.
SES / AES / QES guidance for customers and teams.
How Aria and Sentinel meet transparency duties.
Master ISMS policy — objectives, roles, principles.
Security, privacy, engineering, and people policies.
Vendors that process customer data on our behalf.
Will be available to qualified prospects under NDA once issued.
Certification programme in progress — certificate not yet issued.
External pentest report summary under NDA after first engagement.
Enterprise due-diligence pack — request from security.
Key vendors that process customer data. Full register and notification rules are in the DPA.
Changes are notified per DPA (typically 30 days). Questions: legal@touch2sign.com
From the 18-month SOC 2 / ISO programme — public milestone view.
Deeper programme docs (internal): Compliance Programme Hub · Product security deep-dive
We can walk through architecture, data flows, sub-processors, and the certification roadmap. Request questionnaires or NDA documents from the security mailbox.