Signelio publishes its current trust posture, legal policies, and evidence-oriented workflow controls so customers can evaluate the platform against real implemented behavior instead of assumed future capabilities.
Current Trust Signals
The items below reflect the current trust signals and operational controls surfaced in the product and public documentation. If you need contractual assurances or environment-specific answers, request them directly from the team.
Encrypted Delivery
Document access flows use encrypted connections with controlled delivery for authenticated and public signing sessions.
Audit Evidence
Completed packages include a signed PDF plus certificate, manifest, and audit history for downstream review.
Workspace Access Controls
Workspace membership, recipient verification, and route-scoped signing access help limit document exposure.
Public Policy Transparency
Privacy, terms, refund, cookie, GDPR, and compliance information are published through dedicated public routes.
Compliance Settings
Retention defaults, audit exports, and related compliance controls are managed through the authenticated settings surface.
Enterprise Planning
SSO, security questionnaires, and larger trust reviews are handled as coordinated enterprise engagements.
1. Encryption & Data Protection
Document and signing flows use encrypted transport and managed storage. Original files and evidence assets remain behind authenticated delivery, while preview assets are only allowed through cache-safe paths when they are explicitly marked for that use.
2. Access Controls & Authentication
Workspace-level roles, authenticated sessions, and route-scoped recipient access are used to control who can view or act on documents. Public signing links store hashed tokens, and enterprise identity needs such as SSO are coordinated with the team rather than exposed as a self-serve toggle.
3. Audit Trail & Logging
Signing activity is recorded as an append-only event chain with linked hashes across document lifecycle events. Completed packages surface audit history alongside certificate and manifest artifacts, and compliance settings provide export-oriented workflows for evidence review.
4. Infrastructure & Availability
The platform runs on managed cloud infrastructure and publishes customer-facing incidents through the public status page. Cache-safe media delivery is separated from protected originals so signed workflows can stay responsive without treating every document asset as public content.
5. Vendor & Third-Party Management
Signelio relies on third-party infrastructure and delivery providers where needed to operate the service. Data-processing and security questions that depend on those vendors should be validated through support or compliance review instead of assumed from generic platform claims.
6. Incident Response & Breach Notification
Operational issues are investigated through support and the public status surface, with incident updates published when customer-facing impact exists. Security or breach handling follows applicable legal obligations and contractual commitments in effect for the affected customer relationship.
7. Employee Security & Training
Administrative and operational access is governed through internal process rather than exposed in the product UI. If your review requires detailed answers about personnel controls, onboarding, or internal security operations, request a current questionnaire response from the team.
8. Penetration Testing & Vulnerability Management
Security review and vulnerability handling are ongoing operational responsibilities, but exact testing cadence and remediation commitments should be confirmed directly for your engagement. Public copy on this page is intentionally limited to controls and workflows that are visible or supportable from the current product surface.
9. Data Residency & Sovereignty
If your organization has residency, sovereignty, or regional processing requirements, scope those needs with the team before relying on a specific storage jurisdiction. Regional handling and related contractual controls are not presented as self-serve guarantees in the current product surface.
10. Compliance Inquiries & Reports
For compliance documentation requests, security questionnaires, or to report a vulnerability, please contact our security team. We are committed to transparency and will respond to all inquiries within two business days.
Security Team
support@sign-mobile.space
AFFSPACE LIMITED
1804, 18/F, OFFICE PLUS,
93-103 WING LOK STREET,
SHEUNG WAN
HONG KONG
Business Number: 79899280