Security & Compliance

Built for documents you have to defend.

Every signed document ships with a defensible audit trail. ESIGN Act and UETA compliant. SHA-256 tamper detection. Encryption in transit and at rest. This page is what we actually do, not what we wish we did.

ESIGN
Act compliant
UETA
49 states
SHA-256
Tamper detection
TLS 1.3
In transit
01

Encryption

In transit

All connections to docrunner.io and app.docrunner.io use TLS 1.2 or higher (TLS 1.3 preferred). HSTS enforced. Modern cipher suites only. Insecure protocols disabled at the load balancer.

At rest

Document files stored on AWS S3 with server-side AES-256 encryption. Application database (PostgreSQL on Render) uses encrypted volumes. Daily encrypted backups.

02

Audit trail & Certificate of Signature

Every completed signing packet generates an auto-attached Certificate of Signature. Captured on every signer event:

  • Signer name and email address
  • IP address at consent and at each signature
  • Browser user agent string
  • Timestamps (sent, viewed, signed, completed)
  • ESIGN consent disclosure record
  • Signer's typed or drawn signature image
  • SHA-256 hash of the executed PDF
  • Audit trail exportable as JSON

The Certificate of Signature PDF and the underlying audit trail JSON are both archived alongside the signed packet on the monday.com board row.

03

Compliance

ESIGN Act (15 U.S.C. § 7001)

U.S. federal law that gives electronic signatures the same legal weight as ink. Signer consent disclosure is shown and captured before signing begins. DocRunner is compliant by default.

UETA (Uniform Electronic Transactions Act)

State-level e-signature law adopted by 49 of the 50 U.S. states. DocRunner captures the consent-to-transact-electronically record required for UETA.

SHA-256 tamper detection

Every executed PDF is hashed with SHA-256 at the moment of completion. The hash is recorded in the Certificate of Signature. Any byte-level change to the signed PDF afterwards produces a different hash, allowing tamper detection.

Roadmap items (not yet certified)

SOC 2 Type II, HIPAA, and eIDAS Advanced/Qualified e-signature certifications are on the roadmap but not in place yet. If your procurement requires one of these, talk to us about timeline.

04

Data residency & subprocessors

All customer data is stored in the United States. We use the following subprocessors to operate the service:

AWS S3

Document file storage. AES-256 server-side encryption.

Render

Application hosting + PostgreSQL database. US region.

SendGrid

Transactional email delivery for signing invitations and reminders.

Stripe

Subscription billing. We do not store payment card numbers.

Plausible

Cookieless website analytics. No personal data collected.

Google Analytics

Aggregate marketing-site usage. Sets _ga cookies.

See the Privacy Policy for the full data flow.

05

Security disclosure

Found a vulnerability? Email security@docrunner.io with reproduction steps. We'll acknowledge within 1 business day and work with you on coordinated disclosure. We do not run a paid bounty program yet, but we recognize responsible disclosure publicly when the reporter wants the credit.

Honesty section.

We're an early-stage product. We don't yet have SOC 2 Type II, HIPAA BAA, or eIDAS qualified-signature certification. We do have the foundational controls (encryption, audit trails, compliance disclosures) and we're building toward the certifications. If your procurement requires a specific certification today, ask us about the timeline before you start a trial.

Ask about a specific compliance requirement →

Ready to streamline your signing?

Set up in minutes. No credit card required.

Get Started Free View Pricing