GDPR / UK GDPR
AvailableOperational privacy programme: DPA, ROPA, DPIA, DSAR and breach procedures.
Processor for signing workflows under customer instruction; controller for accounts, billing, and platform security.
What is live today for Touch2Sign — and what is still in progress. We do not mark SOC 2 or ISO 27001 as certified until reports exist.
Status is operational readiness — not a marketing badge. Out of scope means we do not claim it by default.
Operational privacy programme: DPA, ROPA, DPIA, DSAR and breach procedures.
Processor for signing workflows under customer instruction; controller for accounts, billing, and platform security.
Product supports SES, AES, and QES via QTSP partners — eIDAS-aligned, not “eIDAS certified”.
QES via eID Easy; UK AES via OneID (DIATF Medium) with PAdES sealing.
Bank-verified UK identity through OneID, certified under the UK Digital Identity and Attributes Trust Framework.
Transparency mapping for Aria / Sentinel published; counsel review of messaging still open.
ISMS policies, scope, risk register, and operating model in place. Certification audit not started.
Target: Stage 1 ~Month 10; certificate ~Month 18.
Control design and evidence logging underway. No SOC report available yet.
Reports will be shared under NDA when issued.
We help in-scope customers meet supplier due-diligence expectations; we do not claim entity certification under NIS2 or DORA.
Default out of scope — no PHI, no BAA unless expressly agreed in writing.
Product, infrastructure, privacy, and operations — what we run today.
| Control | Category | Status |
|---|---|---|
| Encryption in transit (TLS) HTTPS / TLS for application and API traffic. |
Infrastructure | Available |
| Encryption at rest AES-256 class encryption for documents and database volumes (AWS). |
Infrastructure | Available |
| Document integrity hashing SHA-256 hashing and tamper-evident signed artifacts. |
Product | Available |
| Cryptographic PDF signatures (PAdES) AES/QES flows embed signatures in the PDF — not audit-trail only. |
Product | Available |
| Audit trail & SCCR Per-document event log, Signer Completion Certificate, evidence pack export. |
Product | Available |
| Identity verification tiers Email/SMS OTP, OneID (UK DIATF), eID Easy national eID / QES. |
Product | Available |
| Admin MFA TOTP required for organisation admins and platform staff. |
Product | Available |
| DSAR tooling Org-level DSAR register, 30-day SLA tracking, export packs. |
Privacy | Available |
| Retention & legal hold Configurable retention, pre-purge notices, per-document legal hold. |
Privacy | Available |
| EU data residency (primary) Primary hosting on AWS eu-west-1 (Ireland). |
Infrastructure | Available |
| Breach notification procedure GDPR Art 33–34 playbook targeting 72-hour notice where required. |
Privacy | Available |
| Change management Release checklist and production change log. |
Operations | Available |
| Access reviews Quarterly access review log established. |
Operations | Available |
| Incident response tabletop IR plan drafted; first tabletop in progress. |
Operations | In progress |
| Backup / DR restore drill BCP documented; first RDS restore drill scheduled. |
Operations | In progress |
| External penetration test Annual external pentest planned; summary under NDA. |
Operations | Planned |
| Vendor SOC / ISO collection Collecting current reports from key sub-processors. |
Operations | In progress |
Public documents and items available on request or under NDA when ready.
How we collect and use personal data.
Customer terms, acceptable use, and eIDAS disclaimers.
Art 28 DPA, processing records, platform DPIA, ISMS and product policies.
Enterprise due-diligence pack for procurement.
Will be available to qualified prospects under NDA once issued.
Certification programme underway — certificate not yet issued.
External pentest report summary under NDA after first engagement.
Vendors that process customer data on our behalf. Full detail in the DPA on request.
| Vendor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, storage, email, auth, monitoring | EU (Ireland) eu-west-1 |
| OneID Limited | UK bank identity verification (AES) | United Kingdom |
| eID Easy / Dokobit | QES signing & EU national eID | EU |
| NMI | Preferred SaaS payment rail | US (card vault at processor) |
| Stripe | Alternate payment processing | US / EU |
| Anthropic | Optional document Q&A (Aria) | USA (SCCs) |
| AWS SNS | SMS OTP and alerts | EU |
Milestones from our compliance programme — dates are targets, not guarantees.
| Milestone | Target | Status |
|---|---|---|
| Policies v1.0 + ISMS scope | Jul 2026 | Done |
| Customer legal pack (Privacy, Terms, DPA, Refunds) | Aug 2026 | Done |
| ROPA + DPIA published | Aug 2026 | Done |
| IR tabletop exercise | Q3 2026 | In progress |
| RDS restore drill | Q3 2026 | Pending |
| External penetration test | Month 5 | Pending |
| SOC 2 Type I | Month 9 | Pending |
| ISO 27001 Stage 1 | Month 10 | Pending |
| SOC 2 Type II + ISO certificate | Month 18 | Pending |
Email security@touch2sign.com for questionnaires, NDA reports when available, or a walkthrough of our controls.
Contact securityProduct deep-dive (OneID, QES, eWitness evidence) lives with the product team. Privacy: privacy@touch2sign.com · Legal: legal@touch2sign.com