Compliance & Trust at Signomate
We are committed to maintaining the highest standards of compliance. Explore the sections below to understand our practices and policies.
1. Electronic-Signature Legal Compliance
Regulation / Standard | What we guarantee today |
---|---|
EU & UK eIDAS — Article 25 | Our basic workflow captures intent, consent, a tamper-evident audit trail and immutable file hash, satisfying the legal requirements for Simple Electronic Signatures (SES) in all EU Member States and the UK. |
U.S. ESIGN Act & UETA | Each signature is an electronic “sound, symbol or process” adopted with intent; users receive clear e-records consent and a copy of the executed document. |
Canada — PIPEDA Part 2 | Signomate provides an auditable, integrity-protected record that fulfils the general statutory definition of an electronic signature across Canadian provinces and territories. |
Road-map: Integration of certificate-based, Advanced/Qualified signatures (e.g. BankID, QTSP digital certificates) is in active development. Until it launches, please treat Signomate signatures as Simple / Basic for legal classification purposes.
2. Data Protection & Privacy
- GDPR & UK-GDPR: Data minimisation, purpose limitation and robust Data Processing Agreements (DPAs) with sub-processors.
- CCPA/CPRA & other US state laws: Dedicated processes for consumer access/deletion requests.
- Encryption everywhere: TLS 1.3 in transit; AES-256 at rest; customer files stored in logically isolated buckets.
- Data locality options: Choose EU-only, UK-only or North-American hosting to address residency obligations.
See our Privacy Policy for full details.
3. Secure Infrastructure
- Cloud hardened: Hosted on DigitalOcean infrastructure — workloads run in ISO/IEC 27001:2013-audited, SOC 2 Type II-certified data centers with automated backups and optional cross-region failover.
- Zero-trust network: Services mutually authenticate and use short-lived tokens; no open lateral movement paths.
- 24/7 monitoring: Real-time threat detection, automated patch management and quarterly external penetration tests.
4. Your Responsibilities
Signomate supplies the compliant toolbox; you remain the data controller and document owner. Please ensure that:
- Document suitability: E-sign only documents that are legally permitted to be signed electronically in your jurisdiction.
- User access governance: Review signer and admin permissions regularly; revoke unused accounts.
- Retention rules: Store executed documents for the statutory period required in your industry/region.
- Internal policies: Align Signomate usage with your own information-security and privacy policies.
For more detailed information, please refer to our Privacy Policy, Terms of Service, and Cookie Policy.
5. Questions?
Our Compliance team is happy to help. Reach us at support@signomate.com.
Frequently Asked Questions
Questions About Compliance?
Our team is here to help. Contact us for more information on how Signomate meets your compliance needs.