Security & Privacy

Built to be trusted
with your documents.

Your documents are encrypted in transit and at rest, processed privately, and auto-deleted after anonymous use. Every signature is auditable.

TLS 1.3 in transit AES-256 at rest 30 min auto-delete SHA-256 audit trail
Data protection

Protected at every stage.

Multiple layers of security protect your documents from the moment they leave your device to the moment they are deleted.

Encryption in transit & at rest

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Your files are protected from the moment they leave your device.

Zero-retention policy

Files are automatically deleted from our servers within 30 minutes of processing. We never store your documents permanently.

Private by default

Anonymous files are processed and deleted automatically — no account required, and your files are never stored or used to profile you. Persistent storage only happens when you sign in and opt in.

Auditable signatures

Every completed signature includes a tamper-evident audit trail and a certificate of completion, aligned with the ESIGN Act and eIDAS framework.

Upload TLS 1.3 Encrypted storage Isolated processing Secure download Auto-delete
Standards we build to

Designed around recognized frameworks.

We design to recognized data-protection and e-signature frameworks.

GDPR
EU data-protection practices
eIDAS
EU eSignature framework · aligned
ESIGN Act
US eSignature law · aligned

Formal certifications are in progress and not yet claimed as complete. Data Processing Agreements are available on request.

eSignature security

Legally binding, cryptographically provable.

Our electronic signatures are designed to align with the ESIGN Act (US), eIDAS (EU), and other global electronic signature frameworks — and every completed document carries its own proof.

  • ESIGN Act, UETA & eIDAS aligned
  • Tamper-evident audit trail — timestamps, IP addresses, activity logs
  • SHA-256 hash verification detects any change made to a document after signing
  • Certificate of completion with every completed document
  • Email one-time-code verification for invited, unauthenticated signers
Sample certificate · illustrative ● sealed
documentVendor Agreement.pdf
sha-2569f3a…c1e7
signed2026-06-12 14:02 UTC
signer ip203.0.113.42
integrityverified

Example record — not a real customer document.

For teams

Enterprise security controls.

Additional controls for Business and Enterprise customers.

01

Multi-factor authentication

Protect accounts with two-factor authentication using any TOTP authenticator app, plus single-use backup codes.

02

SSO integration coming soon

Single Sign-On with SAML 2.0 for Okta, Azure AD, Google Workspace, and other identity providers — on the roadmap, not yet available.

03

Role-based access control

Granular permissions control who can access, edit, and sign documents. Define custom roles for your organization.

04

Admin dashboard

A centralized panel for managing users, monitoring activity, and enforcing security policies.

Talk to us

Questions about security?

Our team is here to help — contact us for a detailed security review or to discuss your compliance requirements. To report a vulnerability, email security@lexosign.com.