In transit
TLS 1.3 on every request. HSTS enabled. HTTP redirects to HTTPS. No mixed content.
The database, file storage and authentication system that hold your account, documents and audit trails are hosted in Sydney, Australia (AWS region ap-southeast-2), through Supabase. We don't replicate, mirror or back up your data to any other region.
A small number of supporting systems necessarily touch global infrastructure, the static website (Vercel CDN), the TLS edge proxy (Cloudflare), the outbound email pipeline (Google Workspace SMTP) and payment processing (Stripe). The full breakdown is in our privacy policy, section 6. We've kept the list short so the trust story stays clear.
TLS 1.3 on every request. HSTS enabled. HTTP redirects to HTTPS. No mixed content.
The Supabase database and storage buckets we use are encrypted at rest by AWS using AES-256.
Every event in a document's lifecycle, sent, viewed, disclosure accepted, signed, completed, is recorded with:
prevHash) to the hash of the previous event.This chains every event to the one before it. If a single byte of the audit log is altered after the fact, including by us, the chain breaks and the audit page flags it. Anyone can re-verify the chain from the public Audit page using only the data on screen.
Every row in our database is protected by a server-side Row-Level Security (RLS) policy that ties it to the workspace it belongs to. A user signed into one workspace cannot read another workspace's data, even by guessing IDs in the URL. Anonymous signers can only access the specific document their sign-token unlocks, never anyone else's.
We never see, log or store your password in plain text. Supabase Auth handles password verification and stores a salted bcrypt hash. Two-factor authentication is on the roadmap for the Business plan but is not live yet.
Every email we send from signpad.com.au is signed with DKIM, aligned with SPF and protected by DMARC. This is what stops your signing emails being marked as spam or spoofed.
Supabase performs automatic daily backups of the production database in its hosted Sydney region. Backups are encrypted with the same AES-256 standard as live data. We have not configured cross-region backup replication.
The third parties we share customer data with, and what each receives:
If we ever add or change a vendor, we'll update this list and the version number at the top of the page.
If you've found a security issue, please email sign@signpad.com.au with the subject line "Security: [short summary]". We respond within 2 business days. We don't yet run a paid bug bounty but we'll send a thank-you and credit you on this page if you'd like.
If we ever experience a data breach that's likely to result in serious harm, we'll notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, in line with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). See privacy policy section 15.
Things we want to ship in the next 12 months. These are roadmap items, not current state:
Security questions: sign@signpad.com.au. We answer every message.