Back to Home

Security

Security

How VollSign protects your data and your clients' documents.

Infrastructure

Hosted in Germany

All servers are located in German data centers (Hetzner).

TLS 1.3 Everywhere

Every connection between your browser and our servers is encrypted with TLS 1.3.

AES-256 Encryption at Rest

Documents and personal data are stored encrypted at rest using AES-256.

Automated Backups

Daily encrypted backups with a 30-day retention policy and tested restore procedures.

Application Security

Role-Based Access Control

Granular permissions for every role — lawyers, assistants, and clients each see only what they need.

Two-Factor Authentication

Optional 2FA via TOTP for lawyers and firm admins.

Audit Logs

Every document action — creation, view, sign, revoke — is logged with timestamp and user identity.

Secure Session Management

Short-lived session tokens with automatic expiry and server-side revocation.

Development Practices

Dependency Scanning

All dependencies are scanned for known vulnerabilities on every CI run.

Code Reviews

Every code change goes through peer review before deployment.

Penetration Testing

Annual third-party penetration tests with remediation tracked to closure.

Report a Vulnerability

Found a security issue? Please disclose it responsibly. We review all reports and respond within 5 business days.

Security Disclosure