One page for procurement, security and legal teams. Standards link to their source. Audit status is current, not aspirational. The DPA, sub-processor list and AI policy are public.
01 · Availability targets
Availability targets for each platform component. For current status or incident history, contact [email protected] — a public status page is on the roadmap.
Subscribe to incident notifications: [email protected]
02 · Compliance & attestations
Each entry below states what is active, what is in progress, and which standard it maps to. We do not display certifications we do not hold.
SOC 2
Type II
Type I controls implemented and operating. Type II audit preparation is underway with an external CPA firm. Current status and evidence available under NDA upon request.
ISO 27001
Controls
Annex A control set implemented and mapped against our ISMS. External certification audit scheduled following SOC 2 Type II closure.
GDPR
Compliant
Article 28 Data Processing Agreement available below. Standard Contractual Clauses (SCCs 2021/914) included for international transfers. EU data residency available.
DPDP Act
India
Designed for the Digital Personal Data Protection Act 2023. Indian data residency, consent-management primitives, and Significant Data Fiduciary obligations supported.
eIDAS
Advanced
Advanced Electronic Signature (AdES) implementation aligned to Regulation (EU) 910/2014. Qualified signatures (QES) are on the roadmap via accredited Qualified Trust Service Providers and are not offered today.
ESIGN · UETA
US
Compliant with the Electronic Signatures in Global and National Commerce Act (ESIGN, 15 U.S.C. § 7001) and the Uniform Electronic Transactions Act (UETA) as adopted by 49 US states.
HIPAA
Aligned
Administrative, physical and technical safeguards aligned to 45 CFR §§ 164.308–312. Business Associate Agreement available on enterprise plans.
Audit trail
Hash chain
Every envelope action is recorded in a tamper-evident, hash-chained audit trail. Each event hash covers all material fields and links to the previous event, so removal or alteration is detectable on verification.
03 · Security controls
AES-256-GCM via cloud-provider KMS. Per-tenant data keys with envelope encryption.
TLS 1.3 only on all public endpoints. HSTS preload, perfect forward secrecy, modern cipher suites.
BYOK / customer-managed keys (CMK) on enterprise plans. Annual key rotation, audited.
SSO via SAML 2.0 / OIDC, SCIM provisioning, granular RBAC, IP allow-listing, step-up MFA on signing events.
Tamper-evident, append-only audit log of every access and signing event. Exportable in CEF, JSON and CSV.
Tenant-pinned residency in US (us-east-1), EU (eu-central-1) and India (ap-south-1). No cross-region replication without consent.
Annual third-party penetration test by an independent CREST-accredited firm. Executive summary available under NDA.
Continuous SCA + SAST + DAST. Dependency patching SLA: critical < 24h, high < 7d. Responsible disclosure at [email protected].
04 · AI safety & data handling
AI is the third rail of enterprise procurement in 2026. Here is exactly what we do and do not do — contractually guaranteed in our DPA.
Customer documents, signatures, audit logs and metadata are never used to train foundation models — ours, our vendors', or anyone else's. This is contractually guaranteed in our DPA and enforced via zero-retention API agreements with our model providers.
AI inference for an envelope runs in the customer's tenant region. EU tenants do not see their data routed to US inference endpoints. Region routing is enforced at the edge.
AI context windows are scoped to a single request and discarded immediately. We do not maintain persistent embeddings of customer contracts unless the customer explicitly enables semantic search (and even then, embeddings live in the tenant's region only).
We pin to specific model snapshots (e.g. gpt-4.1-2025-04, claude-sonnet-4-5-20250929). Upgrades require change management and customer notification on enterprise plans.
AI cannot finalize, send for signature, or execute a contract without explicit human approval. AI is an assistant, not an actor.
Model provider contracts: we operate on the zero-retention API tier with OpenAI and Anthropic, and have signed enterprise DPAs with both. Customer prompts and completions are not retained beyond the request lifecycle and are not eligible for model training.
05 · Data processing
Our DPA is GDPR Article 28 compliant and incorporates the European Commission's 2021 Standard Contractual Clauses for international transfers. It governs the processing of personal data when you use ZiaSign as a Processor.
06 · Sub-processors
We disclose every sub-processor that may process customer personal data. Customers can subscribe to change-notifications and have a 30-day objection window before any new sub-processor goes live.
| Processor | Purpose | Regions |
|---|---|---|
| Amazon Web Services (AWS) | Primary cloud infrastructure | us-east-1, eu-central-1, ap-south-1 |
| Microsoft Azure | Secondary infrastructure, AKS for control-plane services | EU North, India South |
| OpenAI | AI inference (clause extraction, summarization) | Customer-region routing, no training opt-in |
| Anthropic | AI inference (review-side reasoning) | US, EU; zero-retention API tier |
| Resend | Transactional email delivery | EU |
| Cloudflare | Edge CDN, WAF, DDoS protection | Global |
07 · Responsible disclosure
Acknowledge
< 24h
Initial response from a security engineer
Triage
< 72h
Severity assigned, repro confirmed, ticket opened
Patch SLA
Critical < 24h
High < 7d · Medium < 30d · Low next release
Report security issues to [email protected]. PGP key available on request. We commit to non-retaliation against good-faith researchers and will credit reporters in our hall of fame on request.
08 · Contact
[email protected]
Security & vulnerability disclosure
[email protected]
Privacy, GDPR & DPDP requests
[email protected]
Counter-signed DPA, MSA, BAA
[email protected]
Vendor security questionnaires
Last reviewed: 23 April 2026 · Page is updated within 5 business days of any material change.