Signful

Trust & Security

Privacy Policy & Data Protection

Signful is built on the principle that cryptographic proof is superior to blind trust. We minimize the data we collect, purge document bytes aggressively, and never monetize or train on your files.

Last updated: September 2026

1. Data Location & Hosting

All documents and derivatives are stored encrypted in Cloudflare R2 object storage with global automatic distribution. Metadata and audit records reside in dedicated PostgreSQL databases hosted via Supabase in the US-East (Virginia) region. Application logic executes on Vercel's global edge and serverless network.

2. Document Retention & Auto-Purging

By default, anonymous PDF verification uploads are hard-purged from object storage after 7 days. Envelopes created on the free tier are retained for 7 days active and purged after 30 days unless an organization has an active paid plan. Our automated daily purge daemon removes the document bytes permanently while retaining cryptographic hash-only proofs (SHA-256 fingerprints, ByteRange data, verdict) so you can verify artifact integrity without storing sensitive contents.

3. Backups & Disaster Recovery

Database metadata is backed up continuously with automated point-in-time recovery (PITR). Document object storage is replicated across multiple availability zones. Expired or deleted documents are excluded from long-term backup archives.

4. Third-Party Subprocessors

We strictly limit third-party subprocessors to essential cloud infrastructure: Cloudflare (object storage), Supabase (PostgreSQL database & authentication), Stripe (payment processing and billing portal), Resend (transactional email delivery for signature invites and notifications), and Vercel (application hosting and serverless compute). We do not sell data or share customer documents with any advertising or analytics brokers.

5. Encryption & Cryptographic Integrity

All data in transit is encrypted using TLS 1.3. Stored documents are encrypted at rest using AES-256. Audit trails utilize HMAC-SHA-256 event chaining where each signature, view, and seal event is cryptographically linked to the previous event, guaranteeing verifiable tamper detection.

6. Access Controls & Tenant Isolation

Strict Row Level Security (RLS) policies are enforced at the database level to ensure tenant isolation. Employees and operators have zero access to customer document payloads. Access to serverless infrastructure is secured by short-lived credentials and multi-factor authentication.

7. Breach Notification Commitment

In the event of a confirmed security incident or unauthorized access affecting customer data, Signful will notify impacted account administrators within 72 hours of verification, providing relevant incident details and remediation steps.

8. Right to Deletion & Data Portability

Account owners may request full account and document deletion at any time. When a document or envelope is deleted, the underlying object files are immediately purged from R2 storage and associated database records are unlinked.

9. Strict No-AI-Training Guarantee

We never use customer documents, signatures, names, email addresses, or audit data to train, fine-tune, or evaluate machine learning or artificial intelligence models. Your documents belong solely to you.

Questions or Data Inquiries?

For security inquiries, subprocessor agreements, or deletion requests, reach out to our team at security@signful.co.