Trust
Security at Psygned
Last updated 19 September 2026
Psygned handles contracts, so this page says plainly what protects them, where the limits are, and how to reach us if you find a problem. It is written for the person deciding whether to trust the service, not for a procurement checklist, though it answers most of those questions too.
Where your data lives
Documents, signatures, the evidence record and account data are stored in Ireland (Amazon Web Services eu-west-1, operated for us by Supabase). The website and API are delivered through Cloudflare's network. Emails are sent through Resend from the mail.psygned.com domain, and card payments are handled entirely by Stripe; we never see card numbers. The full list is on the subprocessors page.
Encryption
Every connection to psygned.com, api.psygned.com and our database uses TLS, enforced with HTTP Strict Transport Security (1 year, preloaded). Files and database volumes are encrypted at rest by the storage provider. Nightly backups are encrypted with a key we hold before they leave our systems. Psygned is not end to end encrypted: like every e-signature service, the server must read the PDF to stamp signatures onto it, so the service can read documents while it processes them, and access to that ability is restricted as described below.
Access control
Access rules are enforced inside the database, not only in the application: every table carries row level security so a sender can only ever read their own documents, and the file bucket is private, so a PDF is only reachable through a signed link that expires in 15 minutes. Signing links are random tokens, personal to 1 signer, stored only as a hash, valid for 14 days and dead the moment the document is completed, declined or cancelled. API keys and passwords are stored hashed. Server code that acts on behalf of a sender checks the sender's session and, when two step verification is on, refuses a session that has not passed it.
Account security
Email confirmation at sign up, a password rule (8 characters with upper case, lower case and a digit), optional two step verification with an authenticator app that is enforced at the database and API level, security notices by email when a password, email address or authenticator changes, secure email change that both addresses must confirm, sign out of all devices, and revocable API keys and assistant connections in Settings. AI assistants connect through OAuth 2.1 with PKCE and never see your password.
Tamper evident records
Once a document is sent it cannot be edited by anyone, including us, through the application. The original and the completed file are fingerprinted with SHA-256 and the fingerprints are printed on the Certificate of Completion, together with every event (sent, opened, disclosure agreed, signed, completed), its time, the device's internet address and browser, and a unique identifier for each signature that also appears on the document itself. Anyone holding the file can verify the fingerprint with standard tools.
Backups and availability
Two independent backups exist. Supabase takes a daily backup of the database, kept for 7 days, on its own platform. In addition, we take our own encrypted backup of the database and every stored file every night, kept for 30 days with a separate provider from the live system, and we restore it into a clean test environment every week to prove it works. The service runs on providers with their own redundancy; we do not yet offer a contractual uptime commitment.
Monitoring
Every server function reports failures to an alerts log, a scheduled health report is emailed to us, and payment, email and signing failures raise alerts the same day. Response headers, a strict Content Security Policy and network protection at the edge reduce the surface for injection and abuse. Rate limits apply to anything that sends email or registers clients.
Testing
The service has been through a structured penetration test covering access across accounts, row level security, request forgery, open redirects, injection through user supplied text, token replay, header leakage and unauthorised spending; every finding was fixed and retested before launch. The test was run by us, not by an independent firm, and we say so here rather than imply otherwise.
Incidents
If a personal data breach affects your data we tell affected senders without undue delay and within 48 hours of becoming aware, with what we know and what we have done, and we notify supervisory authorities where the law requires. The plan for that is written down and reviewed.
Reporting a vulnerability
Email [email protected] with the details, or read /.well-known/security.txt. We answer within 2 working days, fix confirmed issues as a priority, keep you informed, and credit you if you want. Please do not access other people's documents while testing; a test account of your own is free.
What is not in place yet
No SOC 2 or ISO 27001 certification, no independent third party penetration test, no contractual uptime commitment, and account deletion is handled by email rather than a button. Signatures collected through Psygned are standard electronic signatures (ESIGN, UETA and simple eIDAS signatures), not qualified electronic signatures. We would rather list these than have you find out later; ask us about any of them.
Documents
Privacy policy, terms of service, data processing agreement, subprocessors, signer disclosure.