Security

Built for enterprise trust

Every document signed on SignDeal is protected by enterprise-grade encryption, granular access controls, and security practices aligned with the most demanding industry standards.

SOC 2 Aligned
TLS 1.3 · AES-256
24/7 monitoring
GDPR · eIDAS
SOC 2 Security Framework

SOC 2 Type II Certified Infrastructure

AWS

SignDeal runs on Amazon Web Services (AWS), a SOC 2 Type II, ISO 27001 and HIPAA-certified cloud provider. Our internal security program implements the operational controls described in the AICPA Trust Services Criteria (TSC), covering security, availability, processing integrity, and confidentiality.

Questions about our security practices? [email protected]

Security practices

Security practices aligned with the most demanding industry standards.

End-to-end encryption

All documents are encrypted in transit with TLS 1.3 and at rest with AES-256. Key management is handled via AWS KMS, a certified cloud key management service.

Access control & MFA

Granular RBAC, multi-factor authentication for admins, SSO via SAML 2.0 and OIDC, and periodic access privilege reviews.

Continuous monitoring

Real-time monitoring and anomaly alerting tools, with complete action traceability across the platform.

Backups & recovery

Automated backups with configurable retention on AWS high-availability infrastructure, with geographically separated availability zones.

Incident management

Documented incident response procedure. Notification to affected customers within 72 hours. Communication plan and postmortem analysis.

Responsible disclosure

We perform periodic security testing with specialized providers. Active responsible disclosure program. Security patches are treated as a priority.

Infrastructure

Cloud providerAWS (EU-West, Frankfurt)
Data isolationFully isolated tenants
ComplianceGDPR · eIDAS · LSSICE
Uptime target99.9% (best effort)
e-SignaturesQualified & advanced (eIDAS)
Signature certsRFC 3161 trusted timestamping

Security questions?

Our security team is available to answer any questions, provide additional documentation, or handle responsible disclosures.

[email protected]

Standards & compliance

Infrastructure certifications belong to our cloud provider, AWS.

© 2026 DIPLEO TECHNOLOGIES, S.L. All rights reserved.