Skip to content

Security

How we protect your documents

Factual information about how PractiSign handles security, evidence and data protection. No marketing superlatives, just what we do and what we don't claim.

Document access

  • 01All documents encrypted at rest and in transit (TLS 1.2+).
  • 02Scoped, expiring signer tokens. No shared links or guessable URLs.
  • 03Document-level viewing permissions enforced on the server.
  • 04Recipients can only access documents explicitly assigned to them.
  • 05Private file storage with no public caching of document content.

Signing evidence

  • 01Every action timestamped with actor, IP address and user agent.
  • 02Evidence record tied to exact document versions presented to each signer.
  • 03Tamper-evident records: changes after signing are detectable.
  • 04Evidence does not imply that a return was submitted or accounts were filed.
  • 05Email delivery confirmation is recorded separately from document review.

Privacy & data handling

  • 01Document contents, tokens and recipient identities kept out of analytics and error logs.
  • 02No third-party tracking scripts on signing routes.
  • 03Marketing consent is separate and optional, never pre-checked.
  • 04Data retention, export and deletion controls for practice administrators.
  • 05GDPR-aligned processing with documented responsibilities.

Infrastructure

  • 01Tenant isolation between practices. No cross-tenant data access.
  • 02Idempotent operations to prevent duplicate sends or charges.
  • 03Reliable queuing for email delivery and webhook processing.
  • 04Automated backups with tested restore procedures.
  • 05Protected secrets using encrypted server-side credential storage.

Authentication & access

  • 01Staff MFA available for practice accounts.
  • 02Owner, admin and member roles with explicit access rules.
  • 03Unlimited staff does not mean unrestricted document access.
  • 04Session management with appropriate timeouts.
  • 05Audit log of administrative actions.

What we do not claim

  • 01PractiSign provides simple electronic signatures suitable for most UK accounting documents.
  • 02We do not claim to provide advanced (AES) or qualified (QES) electronic signatures unless explicitly stated for a specific workflow with a verified provider.
  • 03A completed signature does not constitute legal advice on whether a specific document requires a particular signature type.
  • 04Evidence records document what happened. They are not independently certified by a third party unless stated.
  • 05Security measures are subject to ongoing review and improvement.

Last reviewed

This page describes planned security measures for PractiSign. Implementation details are subject to provider selection and ongoing security review. This page will be updated as capabilities are confirmed.