Skip to main content

IgniSign Security Overview

This document is dedicated to elucidating the robust security measures and protocols that IgniSign employs to ensure the integrity, confidentiality, and availability of data processed through our platform. It's tailored for a wide audience, ranging from professionals seeking to integrate IgniSign into their workflows to individuals curious about the security underpinnings of digital signatures. Our goal is to provide a comprehensive understanding of the security features that make IgniSign a trusted partner in digital transactions.

Server-side signing with protected keys​

Signatures are created server-side with signing keys kept in a managed key vault. The keys are not exposed to your application or to the signer's device. This approach significantly mitigates the risk of key compromise.

Timestamped Audit Logs​

Maintaining a reliable audit trail is crucial for verifying the legitimacy of digital transactions. IgniSign's platform automatically generates timestamped audit logs for every action performed, providing an immutable record that includes the time, date, and details of each operation. These logs are essential for compliance purposes and can be instrumental in legal proceedings, offering clear evidence of the signing process.

Signing Certificates and Signature Formats​

Signatures are created with the signing key and certificate of the application environment (development, staging or production). The certificate is included in the signature files, so that any verifier can check the integrity of the signed content. The identity of the signer and the evidence of their authentication and identity verification are recorded in the signature proof document and in the audit log, not in the certificate.

Signature files use standard formats: PAdES for PDF documents, and PKCS#7, XMLDSig or JWS for data and hash-only signatures.

Strict Segregation of Users, Signers and Documents per Organizations, Applications and Environments​

IgniSign is committed to providing a secure and customizable signing environment. Our platform supports strict segregation per applications, environments, and levels of signature. This means that data and operations are isolated based on the application environment (e.g., development, staging, production) and the required level of signature security. Such segregation ensures that sensitive information and signing processes are protected according to the specific needs of each application and its environment.

User segregation is a critical component of IgniSign's security strategy, ensuring that data access is strictly controlled and limited to authorized individuals.

This segregation extends to signers, platform users, and end-users, each with defined roles and permissions. By enforcing strict access controls, IgniSign prevents unauthorized access to sensitive information and maintains the confidentiality of the signing process. Explore our Users, Roles, and Rights and Signers documentation for an in-depth understanding of how IgniSign manages user segregation.

Full Privacy Feature​

Recognizing the need for enhanced privacy in certain transactions, IgniSign offers a Full Privacy feature that allows documents to be signed without being shared with or stored on the IgniSign platform. This feature is particularly beneficial for documents containing sensitive information, providing an additional layer of security by ensuring that only the signers have access to the document's content. The Full Privacy mode operates within an Embedded integration mode, further emphasizing our commitment to security and privacy. For more details on how to utilize the Full Privacy feature, please refer to our Full Privacy documentation.

In conclusion, IgniSign's comprehensive security measures, from server-side signing with protected keys to the Full Privacy feature, demonstrate our unwavering commitment to safeguarding the digital transactions of our users. We invite you to explore the referenced documentation for a deeper understanding of each security aspect and to learn how IgniSign can secure your digital signing processes.