Built for legal-grade document workflows
Enterprise-grade encryption, audit trails, and identity verification on every document — designed for teams that need defensible records.
Looking for certifications, policies, and subprocessors? Open the Trust Center →
What's shipped today
Capabilities available now for enterprise due diligence — not roadmap promises.
Audit trail & SCCR
Per-document event log, Signer Completion Certificate (SCCR), and full evidence pack export on every send.
DSAR register & export pack
Org-level data subject request logging, 30-day SLA tracking, and ZIP/PDF/CSV export packs for responses.
Retention & legal hold
Configurable retention from 1 day to indefinite, pre-purge notifications, legal hold per document, auto-delete off by default.
Org admin audit log
Append-only record of branding, retention, team, webhook, and DSAR admin changes with date filters.
White-label sign portal
Business plan — branded sign and witness portals with org logo, colours, background, and font.
Admin MFA
TOTP required for org owners/admins and platform staff before accessing admin consoles.
UK & EU identity flows
OneID (DIATF Medium), eID Easy QES, Signicat, SMS OTP — routed by jurisdiction and document risk.
Security pillars
Encryption & storage
TLS in transit, AES-256 at rest, and SHA-256 document integrity hashing on every signed artifact.
Audit trail
Tamper-evident PDFs, ERSD acceptance logs, SCCR completion reports, and CSV audit exports.
Identity verification
Email OTP to OneID (UK DIATF Medium) to eID Easy national eID — matched to document risk and jurisdiction.
Qualified signatures (QES)
eID Easy delivers eIDAS Qualified Electronic Signatures with PAdES embedded in the PDF — legal gold standard that replaces wet ink for regulated IE/EU flows.
UK deed workflows
eWitness module with attestation declarations, witness evidence packs, and anomaly analysis.
Data residency
Hosted on AWS in UK/EU regions. Data processing agreements available for enterprise customers.
Transparency
Privacy policy, DPA, and sub-processor list published. Breach notification within 72 hours.
Compliance & legal alignment
Electronic signatures (UK & EU)
Touch2Sign supports Simple, Advanced, and Qualified electronic signature flows designed to align with UK Electronic Communications Act 2000 and eIDAS requirements. Signature level should match document risk — legal advice recommended.
Deed witnessing (England & Wales)
eWitness is designed for deed execution workflows under the Law of Property (Miscellaneous Provisions) Act 1989. Remote witnessing requires correct procedural steps — Touch2Sign captures identity evidence and attestation to support your compliance record.
OneID & UK DIATF
Touch2Sign integrates OneID for UK bank-verified identity. OneID is certified under the UK Government's Digital Identity and Attributes Trust Framework (DIATF) at Medium assurance — document-free verification via participating UK banks. Combined with Touch2Sign's PAdES-AES pipeline, identity evidence and cryptographic PDF sealing are captured in one workflow.
eID Easy & Qualified Electronic Signatures (QES)
For Ireland and EU regulated instruments, Touch2Sign routes signers to eID Easy — a QTSP aggregator providing national eID (itsme, BankID, Smart-ID, iDIN, and more) and PAdES-QES sealing. Under eIDAS, QES is legally equivalent to handwritten signature and is Touch2Sign's gold standard for replacing wet ink on high-assurance agreements. Legal advice recommended for your document type and jurisdiction.
Certifications (in progress)
Formal ISO 27001 and SOC 2 certification programmes are in progress. Current security controls are documented in our DPA and available on request for enterprise due diligence.
Full details in our Policy Library, Privacy Policy, Terms of Service, and Data Processing Agreement.
OneID & UK DIATF
UK signers and witnesses can verify through OneID — bank-backed identity certified under the UK Government's Digital Identity and Attributes Trust Framework (DIATF).
What is the UK DIATF?
The Digital Identity and Attributes Trust Framework (DIATF) is the UK Government's standard for trusted digital identity services. It defines assurance levels, fraud controls, and governance so organisations can rely on verified identity evidence in regulated workflows.
How does OneID relate to DIATF?
OneID is certified under the UK DIATF for bank-verified identity at Medium assurance. Signers authenticate through their existing UK mobile banking app — no document scans or new accounts required.
What assurance level does OneID provide?
OneID delivers DIATF Medium assurance via live bank authentication (typically Face ID or fingerprint in the banking app). Touch2Sign records verified name, assurance level, and verification metadata in the audit trail and SCCR.
Is OneID the same as a Qualified Electronic Signature (QES)?
No. OneID provides DIATF-aligned identity proofing suitable for Advanced Electronic Signature (AES) workflows in the UK. For eIDAS Qualified signatures (e.g. many Ireland property instruments), Touch2Sign routes signers to eID Easy national eID methods.
How does Touch2Sign combine OneID with cryptographic signing?
For UK AES flows, Touch2Sign uses OneID for identity verification, then applies a PAdES Advanced electronic seal to the PDF via eID Easy so the signature is cryptographically embedded — not audit-trail only.
When should I require OneID for a signer or witness?
Use OneID for deeds, property transfers, high-value agreements, and eWitness workflows where bank-verified identity strengthens your compliance record. Lower-risk documents can use email or SMS OTP instead.
eID Easy & Qualified Signatures (QES)
For Ireland and EU regulated flows, Touch2Sign delivers eIDAS Qualified Electronic Signatures via eID Easy — the gold standard that replaces wet ink with cryptographically embedded PAdES signatures.
What is a Qualified Electronic Signature (QES)?
Under eIDAS (EU) and retained UK law, QES is the highest tier of electronic signature. It uses a qualified certificate from a trusted service provider and is legally equivalent to a handwritten signature where eIDAS applies — stronger non-repudiation than Simple or Advanced signatures.
Why is QES the gold standard — and can it replace wet ink?
For regulated deeds, property instruments, and high-value contracts, QES embeds a cryptographic PAdES signature in the PDF itself — verifiable in Adobe Acrobat years later. That removes couriers, in-person chasing, scanning, and post errors while binding identity more tightly than ink on paper. Touch2Sign delivers QES remotely via national eID — no branch visit required.
What is eID Easy and how does Touch2Sign use it?
eID Easy is a Qualified Trust Service Provider (QTSP) aggregator. One integration unlocks national eID methods — itsme (Ireland), BankID (Nordics), Smart-ID, Mobile-ID, iDIN (Netherlands), and more — plus the QES signing API. Touch2Sign uses eID Easy for Ireland/EU identity verification and PAdES-QES sealing; for UK AES flows it also applies PAdES-AES after OneID.
Objection: “We always use wet ink for legal documents.”
Wet ink creates weak evidence — no tamper detection, no identity proof, and fragile chain of custody. QES produces a qualified certificate bound to the document hash, with SCCR and audit trail. For Ireland property and many EU instruments, national law expects qualified-level signing; Touch2Sign routes those flows to eID Easy automatically.
Objection: “Our lender or counterparty won’t accept e-signatures.”
Many panels now expect cryptographic evidence, not scanned PDFs. QES PAdES signatures validate in standard PDF viewers and QTSP audit logs. Touch2Sign adds SCCR completion reports, ERSD acceptance, and optional Witness Trail Reports — the evidence pack lenders and compliance teams ask for.
Objection: “QES is too complicated for our clients.”
Signers use familiar national apps they already trust — itsme in Ireland, BankID in Sweden, mobile banking for OneID in the UK. Touch2Sign guides them: review document → verify identity → one-click qualified sign. No certificate installation or technical setup.
How does Ireland deed witnessing work with QES?
Irish regulated deed flows require QES under eIDAS. Signers verify via eID Easy (e.g. itsme); Touch2Sign embeds qualified PAdES in the deed PDF. Witnesses complete a separate QES on an evidence container (.asice) — identity + qualified signature captured for audit.
Is the signature only in the audit trail, or embedded in the PDF?
Touch2Sign requires cryptographic sealing for AES and QES flows — the finished PDF contains PAdES signatures visible under “Signatures” in Adobe Acrobat. Audit certificates (SCCR) supplement the PDF; they do not replace embedded qualified signatures.
Questions about security or compliance?
Our team can walk through architecture, data flows, and due diligence documentation.
Book a security reviewReady to transform how you sign?
Start free today or talk to our team about deed witnessing and enterprise rollout.
