VectorSign

Security & data protection

Last updated: October 5, 2026

Your agreements are some of your most sensitive documents. This page explains, in plain terms, how VectorSign protects them: where your data lives, how it is encrypted and kept separate from other customers, how we use AI, and which companies help us run the service. For how we collect and use personal information, see our Privacy Policy.

1. Where your data lives

VectorSign runs on Amazon Web Services (AWS) in the United States (us-east-1). Your documents, signatures and account data are stored there, in storage that is private by default and never publicly accessible.

2. Encryption

  • In transit. Every connection to VectorSign — the app, the API and every signing link — uses HTTPS (TLS 1.2 or newer). Unencrypted connections to document storage are refused.
  • At rest. Uploaded documents, signed PDFs, certificates and database backups are encrypted with AES-256.
  • Signing links. The secret token in each signer's link is itself encrypted (AES-256-GCM) in our database, so a copy of the database alone does not yield working links.
  • Passwords and keys. Passwords are stored only as bcrypt hashes. API keys and one-time email codes and links are stored only as SHA-256 hashes — we cannot see them.

3. Your organization's data stays yours

Every envelope, document, template and category belongs to exactly one organization. Each request is checked against the signed-in user's organization, and the database itself enforces the same separation as a second line of defense (row-level security). Organization owners control their own settings, such as whether senders may share signing links themselves, and every change is recorded in the organization's activity log.

4. Secure signing

  • Signers need no account: each receives a unique link that expires, and only works when it is their turn in the signing order.
  • For sensitive documents, senders can require an access code, shared with the signer separately; repeated wrong codes lock the link.
  • Accounts are protected by two-factor verification codes, CAPTCHA on sign-in and registration, and the ability to revoke sessions.

5. Proof that holds up

When an envelope is completed, each signed document is sealed with a SHA-256 hash and an independent RFC 3161 timestamp from DigiCert (only the hash is sent to DigiCert, never the document). The audit trail of every view and signature is append-only: our database rejects any attempt to edit or delete it. Anyone can confirm a document is untouched with Verify Integrity, and every completed envelope comes with a Certificate of Completion.

6. How we use AI

  • Only what you type. AI Draft sends the description you type to the AI model to draft a document. Your existing documents, signatures and signed PDFs are never sent to an AI model.
  • Not used for training. We use Anthropic's Claude through Anthropic's commercial service, whose terms prohibit training on our customers' content. Anthropic deletes these requests within 30 days.
  • You stay in control. AI produces drafts only. Nothing is sent for signature until you review and send it, and once a document is sent, AI never changes it.

7. Backups and recovery

The database is backed up automatically every day to encrypted storage, and backups are kept for 30 days. Uploaded documents are versioned, so an accidental overwrite or deletion can be recovered.

8. Who can access your data

VectorSign is built so that our systems, not people, handle your data. Access to production systems is limited to a small number of authorized VectorSign engineers, and is used only to operate, secure and support the service.

9. Companies that help us run VectorSign

We share data with these service providers only as needed to run the service:

  • Amazon Web Services — hosting, document storage, and email delivery.
  • Anthropic — AI drafting, only when you use AI Draft (see section 6).
  • Cloudflare — CAPTCHA protection on sign-in and registration.
  • DigiCert — independent timestamps for signed documents (receives a hash only).

Our marketing website, vectorsign.io, uses Google Analytics to understand visits. The VectorSign app itself does not.

10. Reporting a security issue

If you believe you have found a security vulnerability, please email security@vectorviewer.com. We investigate every report and will keep you updated. Please give us a reasonable chance to fix an issue before disclosing it publicly.