Know who is being asked to sign
Review the recipient name and email before you send. Assigned fields connect each requested action with its intended recipient.
Learn moreImportant documents deserve understandable controls. TextoraSign combines server-side session protection, scoped recipient access, verification, recorded activity, and document-integrity checks across the agreement lifecycle.
Eight practices that work together across the agreement lifecycle — described the way we would want them described to us.
Sign-in uses OAuth 2.0 with PKCE, so authorization codes are bound to the app that requested them.
Traffic between you and TextoraSign travels over encrypted TLS connections.
Recipients reach only the envelope addressed to them through their unique signing link.
Sensitive signing requests can require a code sent to the recipient's email before access.
Views, completions, and follow-ups are recorded so senders can read the document's timeline.
Completed PDFs are assembled and checked so the final record matches what was signed.
We collect what the product needs to work — no selling of personal information, no advertising trackers.
Sessions are managed server-side with HttpOnly cookies instead of long-lived browser tokens.
Review the recipient name and email before you send. Assigned fields connect each requested action with its intended recipient.
Learn moreSigning requests can use email verification codes. Email verification checks access to an inbox; it should not be confused with an independent identity investigation.
Learn moreReview the available document and recipient activity. Opening a signing page and completing a signature are separate events.
Learn moreDownload the final PDF after all required signing and processing have finished. Retain it according to the needs of your agreement and organization.
Learn moreTextoraSign is building its security program toward recognized control frameworks and audit readiness. ISO, FedRAMP, APEC, CSA, PCI, SSAE/SOC, and other third-party certifications or attestations are not presented as achieved unless and until an authorized independent assessment confirms them.
Review the published policies for details about service use and personal information. Contact us when your organization needs additional information.
No. Recipients open their unique signing link, verify access when required, and sign — no account needed.
The agreement's activity view shows available recipient events, so you can read what happened and when.
Connections are encrypted with TLS, and signing sessions are managed server-side.
After all required signing finishes, the completed PDF is assembled, checked for integrity, and available to download.
Your documents are used to provide the service. They are not sold or used for advertising.
Bring the document. We’ll give it a clear path to signed.