Trust Center · Updated 27 August 2026

Security and compliance, in one place

What is live today for Touch2Sign — and what is still in progress. We do not mark SOC 2 or ISO 27001 as certified until reports exist.

Questions: security@touch2sign.com · privacy@touch2sign.com

Request security pack Privacy Policy

Compliance frameworks

Status is operational readiness — not a marketing badge. Out of scope means we do not claim it by default.

Available Live / operational In progress Building towards Planned On the roadmap Out of scope Not claimed

GDPR / UK GDPR

Available

Operational privacy programme: DPA, ROPA, DPIA, DSAR and breach procedures.

Processor for signing workflows under customer instruction; controller for accounts, billing, and platform security.

eIDAS & UK e-signatures

Available

Product supports SES, AES, and QES via QTSP partners — eIDAS-aligned, not “eIDAS certified”.

QES via eID Easy; UK AES via OneID (DIATF Medium) with PAdES sealing.

UK DIATF (via OneID)

Available

Bank-verified UK identity through OneID, certified under the UK Digital Identity and Attributes Trust Framework.

EU AI Act Art. 50

In progress

Transparency mapping for Aria / Sentinel published; counsel review of messaging still open.

ISO 27001:2022

In progress

ISMS policies, scope, risk register, and operating model in place. Certification audit not started.

Target: Stage 1 ~Month 10; certificate ~Month 18.

SOC 2 Type I / II

In progress

Control design and evidence logging underway. No SOC report available yet.

Reports will be shared under NDA when issued.

NIS2 / DORA (customer support)

Available

We help in-scope customers meet supplier due-diligence expectations; we do not claim entity certification under NIS2 or DORA.

HIPAA

Out of scope

Default out of scope — no PHI, no BAA unless expressly agreed in writing.

Security controls

Product, infrastructure, privacy, and operations — what we run today.

Control Category Status
Encryption in transit (TLS)
HTTPS / TLS for application and API traffic.
Infrastructure Available
Encryption at rest
AES-256 class encryption for documents and database volumes (AWS).
Infrastructure Available
Document integrity hashing
SHA-256 hashing and tamper-evident signed artifacts.
Product Available
Cryptographic PDF signatures (PAdES)
AES/QES flows embed signatures in the PDF — not audit-trail only.
Product Available
Audit trail & SCCR
Per-document event log, Signer Completion Certificate, evidence pack export.
Product Available
Identity verification tiers
Email/SMS OTP, OneID (UK DIATF), eID Easy national eID / QES.
Product Available
Admin MFA
TOTP required for organisation admins and platform staff.
Product Available
DSAR tooling
Org-level DSAR register, 30-day SLA tracking, export packs.
Privacy Available
Retention & legal hold
Configurable retention, pre-purge notices, per-document legal hold.
Privacy Available
EU data residency (primary)
Primary hosting on AWS eu-west-1 (Ireland).
Infrastructure Available
Breach notification procedure
GDPR Art 33–34 playbook targeting 72-hour notice where required.
Privacy Available
Change management
Release checklist and production change log.
Operations Available
Access reviews
Quarterly access review log established.
Operations Available
Incident response tabletop
IR plan drafted; first tabletop in progress.
Operations In progress
Backup / DR restore drill
BCP documented; first RDS restore drill scheduled.
Operations In progress
External penetration test
Annual external pentest planned; summary under NDA.
Operations Planned
Vendor SOC / ISO collection
Collecting current reports from key sub-processors.
Operations In progress

Resources

Public documents and items available on request or under NDA when ready.

DPA · ROPA · DPIA · Policy library

Available

Art 28 DPA, processing records, platform DPIA, ISMS and product policies.

Request from legal@ →

SOC 2 Type II report

Planned

Will be available to qualified prospects under NDA once issued.

ISO 27001 certificate

In progress

Certification programme underway — certificate not yet issued.

Penetration test summary

Planned

External pentest report summary under NDA after first engagement.

Subprocessors

Vendors that process customer data on our behalf. Full detail in the DPA on request.

Vendor Purpose Region
Amazon Web Services Hosting, storage, email, auth, monitoring EU (Ireland) eu-west-1
OneID Limited UK bank identity verification (AES) United Kingdom
eID Easy / Dokobit QES signing & EU national eID EU
NMI Preferred SaaS payment rail US (card vault at processor)
Stripe Alternate payment processing US / EU
Anthropic Optional document Q&A (Aria) USA (SCCs)
AWS SNS SMS OTP and alerts EU

Certification roadmap

Milestones from our compliance programme — dates are targets, not guarantees.

Milestone Target Status
Policies v1.0 + ISMS scope Jul 2026 Done
Customer legal pack (Privacy, Terms, DPA, Refunds) Aug 2026 Done
ROPA + DPIA published Aug 2026 Done
IR tabletop exercise Q3 2026 In progress
RDS restore drill Q3 2026 Pending
External penetration test Month 5 Pending
SOC 2 Type I Month 9 Pending
ISO 27001 Stage 1 Month 10 Pending
SOC 2 Type II + ISO certificate Month 18 Pending

Need something for procurement?

Email security@touch2sign.com for questionnaires, NDA reports when available, or a walkthrough of our controls.

Contact security