Skip to main content

Security & data protection

Layered controls for signing workflows

Orbis Sign uses layered controls designed to protect accounts, documents and signing workflows.

Last updated: 10 September 2026

Account and workspace access

Database-user passwords are stored as salted scrypt hashes rather than plaintext. Authenticated sessions are held server-side and identified by an HttpOnly, SameSite=Lax cookie with an eight-hour maximum age and the Secure attribute in production. Optional authenticator-app two-factor authentication is implemented.

Server routes derive the current workspace from an active membership and apply role checks. Separate permissions protect privileged platform functions.

Signing links and evidence

Recipient links use random tokens with an expiry. A Customer can require a one-time passcode for a workflow. Assigned-field checks limit a Signer to fields intended for that Signer or shared fields. The service records express electronic-signing consent and selected status, signing and workflow events.

When completed PDF bytes are available, Orbis Sign records a SHA-256 hash of those bytes. Where they are unavailable, it records a separately labelled completion-event hash. That fallback does not verify PDF contents. A downloadable HTML audit certificate presents available workflow evidence separately from the completed PDF.

Audit data can include timestamps, server-observed or reported network and browser information, recipient details and delivery events where captured. It supports an evidence review but does not conclusively prove civil identity, authority, capacity, location, legal validity or an unbroken chain of custody.

Application safeguards

  • Same-origin Origin or Referer checks for state-changing requests authenticated by session cookie.
  • Origin allow-listing, API security headers and production rate limits for sensitive routes.
  • Server-side input validation on key account, document and signing workflows.
  • Redaction of authorisation and cookie headers from application request logs.
  • Provider-signature verification where Stripe webhooks are used, and fail-closed shared-secret checking for configured Brevo webhooks.

Data handling and infrastructure

Document PDFs are held in PostgreSQL and access is mediated by authenticated application workflows and workspace permissions. Production sessions use secure cookie settings and the API enables HSTS in production configuration.

Orbis Sign does not promise UK-only data residency, a particular hosting or recovery region, encrypted backups, a fixed backup frequency or recovery objective. Customer-specific commitments apply only where they are included in an Agreement.

Important limitations

Security controls reduce risk but no online service can guarantee absolute security. This page is not a certification, independent audit opinion, penetration-test report, service-level agreement or legal warranty. Orbis Sign does not claim ISO 27001, SOC 2, Cyber Essentials or PCI DSS certification.

Permanent individual-document deletion removes operational document records and unreferenced PDF data from the application database while retaining limited metadata-only security evidence. It is not a tenant-erasure or backup-deletion process. A workspace request or in-product status is not confirmation of complete erasure. See the Privacy Policy and Data Processing Agreement.

Report a security concern

Use the contact form and select technical support, or email . Describe the affected feature and impact without including signing tokens, passwords, one-time codes, private documents or unnecessary personal data. No public response-time SLA is promised.

Read legal and trust information