Skip to content
TRUST & PRIVACY

Clarity around
what matters.

Important documents deserve understandable controls. TextoraSign combines server-side session protection, scoped recipient access, verification, recorded activity, and document-integrity checks across the agreement lifecycle.

TLS-encrypted connections Email verification for sensitive requests Complete activity records PKCE-protected sign-in
HOW AGREEMENTS ARE PROTECTED

Protection, in
plain terms.

Eight practices that work together across the agreement lifecycle — described the way we would want them described to us.

  • PKCE-protected sign-in

    Sign-in uses OAuth 2.0 with PKCE, so authorization codes are bound to the app that requested them.

  • TLS in transit

    Traffic between you and TextoraSign travels over encrypted TLS connections.

  • Scoped recipient access

    Recipients reach only the envelope addressed to them through their unique signing link.

  • Email verification

    Sensitive signing requests can require a code sent to the recipient's email before access.

  • Activity records

    Views, completions, and follow-ups are recorded so senders can read the document's timeline.

  • Integrity checks

    Completed PDFs are assembled and checked so the final record matches what was signed.

  • Data minimization

    We collect what the product needs to work — no selling of personal information, no advertising trackers.

  • Server-side sessions

    Sessions are managed server-side with HttpOnly cookies instead of long-lived browser tokens.

FOUR THINGS WORTH UNDERSTANDING

The details, in
their context.

Know who is being asked to sign

Review the recipient name and email before you send. Assigned fields connect each requested action with its intended recipient.

Learn more

Understand the access check

Signing requests can use email verification codes. Email verification checks access to an inbox; it should not be confused with an independent identity investigation.

Learn more

Read activity in context

Review the available document and recipient activity. Opening a signing page and completing a signature are separate events.

Learn more

Keep the completed record

Download the final PDF after all required signing and processing have finished. Retain it according to the needs of your agreement and organization.

Learn more
Security program direction

Controls first. Claims only when verified.

TextoraSign is building its security program toward recognized control frameworks and audit readiness. ISO, FedRAMP, APEC, CSA, PCI, SSAE/SOC, and other third-party certifications or attestations are not presented as achieved unless and until an authorized independent assessment confirms them.

Know the policies.
Ask the right questions.

Review the published policies for details about service use and personal information. Contact us when your organization needs additional information.

COMMON QUESTIONS

Asked about trust.
Answered plainly.

Do recipients need an account to sign?

No. Recipients open their unique signing link, verify access when required, and sign — no account needed.

Can I see who accessed my document?

The agreement's activity view shows available recipient events, so you can read what happened and when.

How is my document protected in transit?

Connections are encrypted with TLS, and signing sessions are managed server-side.

What happens to the signed copy?

After all required signing finishes, the completed PDF is assembled, checked for integrity, and available to download.

Will you add my documents to training data or share them?

Your documents are used to provide the service. They are not sold or used for advertising.

A good place to begin

Your next agreement.
A better experience.

Bring the document. We’ll give it a clear path to signed.