Table of Contents
1Security Overview
PearSign Global Inc operates PearSign, an electronic signature and document workflow service. This page describes application controls and the choices that affect access to your documents.
Security also depends on your organization's settings, the integrations it enables, and how accounts and signing links are used. No service can guarantee absolute security.
2Encryption
- Connections: PearSign uses HTTPS for connections to the Service.
- Passwords: Password sign-in uses salted password hashes, rather than storing passwords as readable text.
- Protected secrets: Authenticator secrets and stored signing-certificate private keys use application-level encryption.
- Document storage: Documents are stored on the server or configured storage service. Storage encryption and backup arrangements depend on the hosting configuration. Contact us for the controls applicable to your organization; this page does not assert per-organization encryption keys or automatic key rotation.
3Authentication & Access
- Two-factor authentication: Accounts can enable an authenticator app and use backup codes for recovery.
- Sessions: Authenticated sessions have expiry and revocation checks.
- Workspace access: Organization membership and role checks determine access to protected workspace features.
- Signing links: A recipient link grants access to its signing workflow. Treat it as private and avoid forwarding it to unintended recipients.
- Login protection: Sign-in endpoints apply rate limits to reduce repeated authentication attempts.
4Infrastructure
The Service uses application servers, a database, and document storage. Organization-scoped queries and database access policies help separate workspace data. Hosting, storage, messaging, and payment providers support delivery of the Service.
Contact help@pearsign.com for information about hosting locations, backup arrangements, and recovery procedures relevant to your agreement. This page does not establish a recovery-time or recovery-point guarantee.
5Electronic signature standards
PearSign provides electronic signature, consent, and audit-record features that organizations can use in their document workflows. ESIGN, UETA, and eIDAS are legal frameworks; naming them is not an independent security certification or a guarantee that every transaction meets their requirements.
Suitability depends on the document, jurisdiction, signer authentication, consent, and other applicable requirements. Our Terms of Service describe the service relationship, and our Privacy Policy explains personal-data handling and privacy rights, including GDPR and CCPA rights where applicable.
6Digital Signatures
- Signing evidence: Document workflows record events such as consent, signing, and completion, with timestamps and available identity and network information.
- Audit integrity: The immutable audit log uses a hash chain to support integrity checks on recorded entries.
- PDF signing: PearSign supports certificate-based PDF signatures. A valid cryptographic signature can help detect changes to the signed bytes; certificate trust depends on the certificate used and the verification software.
- Identity: A document seal does not by itself prove a person's identity. The sender must choose authentication appropriate to the transaction and review the available signing evidence.
7Data Protection
- Document lifecycle: Retention settings and deletion permissions affect which documents a workspace keeps. Download copies you are authorized to retain.
- Deletion requests: The Privacy Policy explains how to request access, correction, export, or deletion.
- Retained records: Organization deletion retains immutable audit history and the promotional send ledger, including recipient email, campaign, and send date. Hashed marketing opt-outs, hashed lifecycle cohort assignments, pseudonymous email-delivery status records, and aggregate reporting baseline counts are also retained. Related account links, organization-specific product and payment outcomes, and reply-case history are removed. Closing an account does not delete copies held by other document parties.
- External processing: AI features can send prompts, conversation context, and document content to configured providers. Review the AI processing disclosure and your organization's settings before supplying information.
We do not represent account closure as immediate erasure from every system or backup. The scope and timing of a request must account for retained records and applicable obligations.
8Monitoring & Incident Response
If you suspect unauthorized access or a security incident, contact help@pearsign.com. Include a description and relevant times, but do not include passwords, private keys, or sensitive document contents in an initial report.
Our Privacy Policy states our breach-notification commitment. Any earlier notification required by applicable law continues to apply.
We operate to a 99.9% internal uptime target. This is an operational target, not a contractual commitment, and PearSign does not currently offer a service level agreement.
9Responsible Disclosure
We welcome security researchers to report vulnerabilities responsibly. If you discover a security issue, please contact us at help@pearsign.com. We commit to:
- Acknowledging your report within 48 hours
- Providing regular updates on our investigation
- Not pursuing legal action against good-faith researchers
- Crediting researchers who help improve our security (with permission)
10Contact
PearSign Security Team
PearSign Global Inc
44 Wall Street
New York, NY 10005, United States
Security inquiries and general support: help@pearsign.com
Signatures that hold up, from the first draft
Prepare documents, collect signatures, and review the completion records available for your workflow.
