How we protect
your documents.
The mechanisms, written down: how signing mail is authenticated, how sealed PDFs prove integrity, where data lives, and who to email when something looks wrong.
Email authentication
Signing requests are sent from swiftsign.ca with SPF, DKIM, and DMARC, so receiving mail servers can verify the mail actually came from us. If a signing email fails authentication, treat it as phishing and report it.
Document integrity
Every completed document is hashed with SHA-256 and bound to a Certificate of Completion that records each signer's name, email, IP address, timestamp, and signature method, backed by a hash-chained, tamper-evident audit log. That record is what makes the signature legally binding under the U.S. ESIGN Act, UETA, and Canadian e-commerce law. Cryptographic in-PDF signing with a publicly-trusted certificate is available for live workspaces that need it.
digest: SHA-256 over the final document bytes
audit trail: signer name, email, IP, timestamp, method
chain: hash-chained, tamper-evident audit log
artifacts: sealed PDF + Certificate of CompletionData location
Documents and sealed PDFs are stored in Cloudflare R2. Accounts, envelopes, and audit records are stored in Neon Postgres. Traffic is HTTPS-only with HSTS.
Deletion on request
Email support@swiftsign.ca from your account address and we delete your documents and account data, subject to legal retention limits. The same right is written into the privacy policy.
Abuse reporting
Got a SwiftSign email you did not expect, or see the service being misused? Email abuse@swiftsign.ca with the message or envelope link. We investigate every report.
New-account limits
Signups are velocity-limited by IP, and new accounts get conservative rate limits on sending. That keeps bulk spam out of the signing channel and keeps signing mail deliverable.
Built to hold up.
Documents signed through SwiftSign are intended to be legally binding electronic signatures under applicable law, including the U.S. ESIGN Act and UETA and Canadian electronic-commerce legislation. Each completed envelope produces a Certificate of Completion recording the audit trail of the signing session. You are responsible for confirming that electronic signatures are valid for your specific document and jurisdiction.