Skip to content
ProductPricing
Compliance

Essentials

  • Evidence and controlsReview legal evidence and security controls.
  • Where inSigner is legalCheck where electronic signatures are recognized.

Country guides

  • United StatesKey framework: ESIGN Act (2000) · UETA
  • AustraliaElectronic Transactions Act 1999 · State and territory ETAs
  • United KingdomElectronic Communications Act 2000 · UK eIDAS Regulations 2016
  • European UnioneIDAS (EU) 910/2014 · eIDAS 2.0 (EU) 2024/1183

Country guides

  • GermanyeIDAS · BGB §126a · Vertrauensdienstegesetz
  • SpaineIDAS · Ley 6/2020
  • FranceeIDAS · Code civil arts. 1366-1367
  • ItalyeIDAS · CAD (D.Lgs. 82/2005)
  • See all countries
Resources

Learn

  • BlogEvidence, signature levels, and how teams send an agreement.
  • Contract templatesStructures you can take to counsel.
  • LearnElectronic signatures in plain language.
  • FAQPlans, evidence, add-ons, and the planned mobile apps.

Explore

  • IntegrationsAPI, webhooks, and optional add-ons.
  • DocumentationHow to send a document and keep the record.
  • Add-onsOTP, WhatsApp signing, and KYC, priced separately.
  • Online signature creatorDraw a signature and download a PNG.

Updates and company

  • ChangelogWhat is available in inSigner today.
  • RoadmapWhat we are planning, without a delivery date.
  • CareersWrite to Nubesti about working on inSigner.
Contact
EN
  • English
  • Español
  • Português
  • Deutsch
  • Français
  • Italiano
Sign inStart free
ProductPricing
Compliance
Evidence and controlsWhere inSigner is legalUnited StatesAustraliaUnited KingdomEuropean UnionGermanySpainFranceItalySee all countries
Resources
BlogContract templatesLearnFAQIntegrationsDocumentationAdd-onsOnline signature creatorChangelogRoadmapCareers
ContactSign in
Home/Legal/Security overview

Trust and signatures

Security overview

How we protect documents and data, how we handle incidents, and how to report a vulnerability.

Updated September 29, 2026Effective September 29, 2026

On this page
  1. Our approach
  2. Infrastructure
  3. Encryption
  4. Access control
  5. Application security
  6. Document integrity
  7. Monitoring and backups
  8. Providers
  9. Incidents and breach notification
  10. Claims we do not make
  11. Reporting a vulnerability

In short

  • Encryption in transit and at rest, and access limited to people who need it.
  • Every completed document carries a SHA-256 hash and an event record.
  • We notify customers of a personal data breach within 48 hours of confirming it.
  • We welcome good-faith security research and will not take legal action against it.

01Our approach

Security at inSigner is built into how the service is hosted, how access is granted, and how signatures are recorded. This page describes our measures in plain language. It is not a certification, and it lists the claims we do not make.

02Infrastructure

Files a customer uploads, including the documents and the completed PDF, are stored in Cloudflare R2, and that storage stays in the European Union. Application hosting, the database, content delivery, and bot challenges use Cloudflare’s global network, including the United States. Amazon Web Services supports some infrastructure and message delivery. These providers operate physically secured data centers and maintain their own independent security certifications. Cloudflare also protects the service against denial-of-service attacks and automated abuse.

03Encryption

Connections to insigner.co, the workspace, the API, and signing pages use HTTPS with modern TLS. Documents and databases are encrypted at rest by the storage providers. Secrets and API keys are kept in managed secret storage, not in source code.

04Access control

Access to production systems follows the principle of least privilege. People who operate the service use individual accounts, administrative access is protected with multi-factor authentication, and access is removed promptly when it is no longer needed. Staff see customer content only when their work requires it, for example to answer a support request the customer opened.

05Application security

We review code before it ships, keep dependencies up to date, validate input, and use bot challenges and rate limits to protect sign-in, signing, and the API. Workspace roles let customers limit who can send, view, and manage documents.

06Document integrity

A completed agreement carries a SHA-256 hash of the file and an ordered record of events, such as when it was sent, opened, and signed, with IP addresses and timestamps. A later reader can compare the file with the record to detect changes. That record is evidence of what the service observed. It is not a qualified certificate and not a statement that a particular law has been satisfied.

07Monitoring and backups

We log security-relevant events, monitor for errors and abuse, and keep backups on a rolling cycle so the service can recover from a failure. Backups are overwritten within 90 days.

08Providers

Before we use a provider that processes customer data, we review its security and sign written data protection terms. The current list is on the subprocessors page.

09Incidents and breach notification

We follow an incident response process to contain, investigate, and fix security incidents. If a personal data breach affects customer data, we notify the affected customers without undue delay and within 48 hours of confirming it. Where Nubesti is the controller, we notify the competent authority within 72 hours where the GDPR requires it, and we tell the people affected when the risk to them is high or when another law requires it.

10Claims we do not make

Nubesti does not claim SOC 2, ISO 27001, HIPAA, or PCI DSS certification for inSigner. Files a customer uploads, including the documents and the completed PDF, are stored in Cloudflare R2, and that storage stays in the European Union. That storage does not make a workflow meet the GDPR. For documents the customer sends, the customer is the controller and Nubesti is the processor. Nubesti is the controller for account, billing, security, support, and marketing. Storing those files in the European Union does not replace an establishment or a representative in the European Union. Payment card data is handled by PayPal and never reaches our systems. A standard signature is not a qualified electronic signature, and QES for Europe is an Enterprise option. We do not publish an uptime credit, a bug bounty amount, or a public status page.

11Reporting a vulnerability

Send reports to hi@insigner.co with the subject “Security”. Describe the issue, the page or endpoint involved, and the steps to reproduce it. Our security.txt file is at insigner.co/.well-known/security.txt. We confirm receipt, keep you informed, and credit you if you want once the issue is fixed.

If you act in good faith, respect these rules, and give us reasonable time to fix the issue before disclosing it, we will not take legal action against you or ask the authorities to. Please do not:

  • Access, change, or delete another person’s documents or data. Use your own test accounts.
  • Run denial-of-service tests, spam, or automated scans that degrade the service.
  • Use social engineering or physical attacks against Nubesti, its staff, or its providers.
  • Keep data you obtained beyond what is needed to show the issue.

Questions about this policy go to hi@insigner.co.

Back to top

Related policies

Responsibilities for electronic signatures

inSigner keeps a workflow and an evidence record. You decide whether it fits the document and the law.

Law enforcement requests

How we respond to requests from authorities for customer data, and when we tell customers.

Disclaimer

The service and these pages are not legal advice and do not guarantee that a signature is effective.

Legal center

Legal center. Terms, privacy, cookies, data processing, identity verification, and signature policies for inSigner, published by Nubesti LLC.

Your documents. Your signatures.
Your control.

A clear electronic signature service for sending, signing, sealing, and verifying important documents.

Start freeDocumentation

Evidence receipt

Agreement completed

Signer
Verified
Timestamp
Recorded
Document hash
7F3A…91C2

01Simple to start

02Unlimited documents

03Evidence-ready

Product

  • Features
  • Pricing
  • Templates
  • API and webhooks
  • Add-ons
  • Signature creator

Resources

  • Documentation
  • Changelog
  • Blog
  • Contract templates
  • FAQ
  • Help Center
  • Roadmap

Company

  • About inSigner
  • Contact
  • Security
  • Enterprise
  • Legal Center
  • Free signing

Popular Guides

  • Where inSigner is legal
  • E-signature legality
  • How to sign a PDF
  • Sign documents online

Explore

  • Integrations
  • Careers
  • Data processing agreement (DPA)
  • Responsibilities for electronic signatures
  • Refunds and cancellation
  • Billing and renewals
  • Cookies policy
  • Accessibility statement

Countries

  • Australia
  • United Kingdom
  • United States
  • Canada
  • European Union
  • Germany
  • France
  • Spain
  • Italy
  • Brazil
  • See all countries
LegalPrivacy PolicyTerms of ServiceDisclaimerSecurityYour privacy choices

© 2026 inSigner. All rights reserved.

Electronic signatures for teams everywhere.

Your privacy, your choice

We use strictly necessary cookies to run this site. With your permission, we also use analytics cookies to improve it and advertising cookies to measure our ads. You can change your choice at any time from Cookie settings in the footer. Read the cookie policy

Your browser sends a Global Privacy Control signal, so advertising stays off unless you turn it on here.

Cookie settings

Choose which optional cookies we may use. Strictly necessary cookies are always on because the site cannot work without them. Read the cookie policy

Your browser sends a Global Privacy Control signal, so advertising stays off unless you turn it on here.

  • Strictly necessary

    Security, bot protection, sign-in, signing sessions, and remembering this choice. Provided by inSigner and Cloudflare.

    Always on
  • Help us understand how the site is used so we can improve it. Provided by Google Analytics and Microsoft Clarity.

  • Measure our ads and show relevant ads on other sites. Provided by Google Ads, Microsoft Advertising, Meta, and TikTok.