Every document signed on SignDeal is protected by enterprise-grade encryption, granular access controls, and security practices aligned with the most demanding industry standards.
SignDeal runs on Amazon Web Services (AWS), a SOC 2 Type II, ISO 27001 and HIPAA-certified cloud provider. Our internal security program implements the operational controls described in the AICPA Trust Services Criteria (TSC), covering security, availability, processing integrity, and confidentiality.
Questions about our security practices? [email protected] →
Security practices aligned with the most demanding industry standards.
All documents are encrypted in transit with TLS 1.3 and at rest with AES-256. Key management is handled via AWS KMS, a certified cloud key management service.
Granular RBAC, multi-factor authentication for admins, SSO via SAML 2.0 and OIDC, and periodic access privilege reviews.
Real-time monitoring and anomaly alerting tools, with complete action traceability across the platform.
Automated backups with configurable retention on AWS high-availability infrastructure, with geographically separated availability zones.
Documented incident response procedure. Notification to affected customers within 72 hours. Communication plan and postmortem analysis.
We perform periodic security testing with specialized providers. Active responsible disclosure program. Security patches are treated as a priority.
Our security team is available to answer any questions, provide additional documentation, or handle responsible disclosures.
[email protected]Standards & compliance
Infrastructure certifications belong to our cloud provider, AWS.
© 2026 DIPLEO TECHNOLOGIES, S.L. All rights reserved.