DealSign← Back to DealSign

Security & Trust

How DealSign protects your documents, your signers, and your signed agreements.

Encryption in transit & at rest

Every document and signature is sent over TLS (HTTPS) and stored encrypted at rest by our storage provider. Nothing travels or sits in plain text.

Secure, per-recipient signing links

Each recipient gets a unique signing link tied to a private token — there are no shared passwords, and one recipient's link can't be used to access another's.

Tamper-evident audit trail

We record a timestamped history for every envelope — when it was sent, first viewed, consented to, and signed — along with the signer's IP address, so every completed document has a verifiable record.

Access control

Only the sender who created an envelope and the recipients it was addressed to can open it. Documents aren't publicly listable or searchable.

SOC 2-certified infrastructure

DealSign runs on infrastructure operated by providers that maintain SOC 2 Type II certification — including Supabase (database & storage) and Vercel (application hosting). Your data lives on audited, enterprise-grade systems.

No data resale

We don't sell your documents, signer information, or contact lists. Your agreements are used only to provide the signing service to you and your recipients.

A note on certifications

DealSign is built on SOC 2 Type II-certified infrastructure, but DealSign itself is not yet independently SOC 2 certified — that's on our roadmap as we grow. We believe in being straight with you: we'll never claim a certification we don't hold. If your organization requires specific compliance documentation, reach out and we'll tell you exactly where we stand.

Have a security question or want to report an issue? Email jack@dealsherpa.app.