Signi and IT security

Modified on Sat, 3 Oct at 2:44 PM

With Signi, your documents are safe. The security of your data is our top priority. We encrypt everything and store it on servers in the European Union.

100% protection. All data flowing into and out of Signi is secured using an HTTPS certificate, and documents are protected by unique hash keys that prevent any manipulation of the content.

Your data never leaves the EU. Signi runs in the Microsoft Azure environment, across two data centers in Europe. MS Azure guarantees the highest level of security and ensures that data is processed only within the EU.

How do we handle your data? The security of your documents and stored data is our main priority. We are fully aware of the sensitivity of the information you enter into the Signi environment.

Every data transfer, every piece of information flowing into and out of Signi is secured using an HTTPS certificate, and documents are protected by unique hash keys that prevent any manipulation of the content. Every signature is immediately logged and stored together with all the data guaranteeing its authenticity and irreplaceability. We keep detailed logs of all activities in the application.

Critical data stored in our databases is encrypted, so no one has access to the open data from your documents.

Legality and binding force. Documents digitally signed using Signi are recognized, valid, and legally binding in almost every industry and civilized country in the world. The digital signature used in the Signi application has the same legal weight and enforceability as a hand-signed paper document. The legal regulation of digital signatures may differ in various parts of the world; we guarantee legality throughout the entire European Union and the USA.

Documents created in Signi are fully compliant with European legislation and are valid, binding, and legally enforceable in the Czech Republic, Slovakia, and the entire European Union. Signi also fully respects European Union Regulation No. 910/2014 (eIDAS) on electronic identification and trust services for electronic transactions in the European market, which also includes the regulation of digital document signing.

GDPR compliant. Signi is fully compliant with GDPR. All processes, terms, documents, and technical solutions comply with this regulation governing the protection of users' personal data. You can also review the complete Privacy Policy.

We hold ISO27001 certification. Every year we undergo certification according to the ISO/IEC 27001 standard by the renowned company DNV, which independently confirms that our information security management system meets internationally recognized standards. We have established and regularly review processes related to the security, storage, and management of data in order to continuously respond to new threats and changes in operations. In accordance with the standard, we have implemented key policies – including, among others, an information security policy, an access management policy, an information classification and protection policy, a backup and encryption policy, a security incident management policy, and a business continuity policy. You can therefore rely on Signi being a secure partner for both companies and corporations.

Compliance with the DORA regulation. The DORA (Digital Operational Resilience Act) regulation targets primarily entities in the financial sector and their ICT service providers. We are not directly subject to this European regulation, yet we have our processes set up to comply with its requirements – especially in the areas of ICT risk management, operational resilience, testing and recording of security incidents, and supplier management. We are thus able to be a reliable and predictable partner for clients from regulated industries, one that does not represent a weak point in their own operational resilience chain.

We meet the lighter regime of the NIS2 regulation. The NIS2 directive increases cybersecurity requirements for selected categories of entities and their suppliers. Even though we are not directly subject to this regulation, we have our processes set up to comply with its principles – from cyber risk management and supply chain security, through incident reporting and handling, to regular training and service continuity. For companies and corporations subject to NIS2, Signi thus makes it possible to use our service without worrying that it would weaken their own regulatory compliance.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article