Volksign supports compliance with the U.S. E-SIGN Act, UETA, HIPAA, and GDPR requirements, and every signature you collect runs on the same enterprise-grade security that protects the rest of your business.
The frameworks that make an electronic signature enforceable and keep the data behind it protected.
The U.S. Electronic Signatures in Global and National Commerce Act (E-SIGN Act) and the Uniform Electronic Transactions Act (UETA) recognise electronic signatures when specific requirements are satisfied. These requirements include: (a) intent to sign, (b) consent to conduct business transactions electronically, (c) a clear connection between the signature and the electronic record, and (d) appropriate retention of records. Volksign supports these requirements as part of its electronic signature process and provides the controls needed for compliant electronic transactions under U.S. E-SIGN and UETA laws.
Regulation (EU) No. 910/2014, known as eIDAS, provides the legal framework for electronic identification and electronic signatures within the UK and the EU. It recognises three categories of electronic signatures: simple electronic signatures, advanced electronic signatures (AES), and qualified electronic signatures (QES). Qualified electronic signatures represent the highest level within this framework. Volksign provides signatures at the QES level.
Volksign is SOC 2 Type II compliant. The latest SSAE 18 SOC 2 Type II report and attestation of compliance are available upon request.
Volksign complies with the General Data Protection Regulation (GDPR) through lawful and transparent processing of personal data for defined and legitimate purposes. Our approach includes appropriate security measures, collection of only necessary information, and support for individuals’ rights to access, correct, and delete their personal data.
The California Consumer Privacy Act (CCPA) provides California residents with consumer privacy rights concerning their personal information and establishes requirements for businesses that collect and process that information. The CCPA became effective on January 1, 2020 and was subsequently amended by the California Privacy Rights Act (CPRA), effective March 29, 2023. Volksign is CCPA-compliant.
The Data Privacy Framework (DPF) Program developed jointly by authorities in the United States, European Union, United Kingdom, and Switzerland, gives U.S. companies a lawful path to receive personal data transferred from the EU, UK, and Switzerland. The European Commission has found the EU–U.S. DPF adequate for protecting that data, which keeps cross-border transfers compliant. Volksign is a certified participant in the EU-U.S. Data Privacy Framework and its UK and Swiss extensions.
Volksign supports healthcare organisations in safeguarding electronic protected health information (ePHI) when it is transmitted through the platform. Volksign is compliant with HIPAA and the Privacy Rule, including the Administrative, Physical, and Technical Safeguards established under the Security Rule.
Volksign supports electronic communication between educators, administrators, school districts, parents, and students while supporting compliance with the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g; 34 CFR Part 99. These requirements help protect the privacy and confidentiality of student education records.
Volksign works with PCI-DSS compliant third-party payment processors to support credit card payment processing within the application.
Organisations can select where their data is stored and processed. Volksign provides data residency options in the United States, European Union and Australia, with security controls applied to each location.
Volksign engages third-party subprocessors to provide certain business and platform services. Each subprocessor is bound by contractual requirements to meet applicable Volksign security controls and data processing standards.
Volksign provides 21 CFR Part 11-compliant workspaces for organisations operating in regulated industries and subject to FDA requirements for electronic records and electronic signatures.
These workspaces support controls such as enhanced signer verification, secure audit trails, and tighter access controls designed to maintain the authenticity, integrity, and confidentiality of electronic records.
Volksign uses FIPS-validated AWS CloudHSM cryptographic services to support document signing. CloudHSM is operated in FIPS mode and is FIPS 140-3 certified. The service also complies with the latest FIPS 186-5 Digital Signature Standard (DSS).
Certifications establish the standard. Volksign backs them with security controls, infrastructure, and systems built to protect your data at every layer.
Volksign production servers run on current Linux systems that receive continuous security patches. Supporting hosted services, including Amazon RDS and Amazon S3, operate on hardened AWS infrastructure-as-a-service (IaaS) environments.
Volksign stores document-related information, including metadata, activity records, original files, and customer data, across separate locations. Documents can also be compiled and generated when requested. Data stored in each location is encrypted at rest using AES-256 encryption together with managed encryption keys.
Volksign follows established software development and quality assurance practices. Development processes incorporate documented procedures and recognised security guidance, including the OWASP framework and its application security recommendations. So every release is held to a consistent security bar.
Volksign applies the principle of least privilege to both software design and employee access. Personnel are instructed to follow the same principle when handling customer support requests, investigating software issues, or working on new product features.
Volksign logically separates its production network from Corporate, Quality Assurance (QA), and Development environments. This separation limits interaction between environments and provides an additional layer of protection around production systems.
Volksign relies on secure external third-party payment processors for payment transactions. Volksign does not process, store, or transmit payment card data.
Volksign monitors its production application and supporting infrastructure 24 hours a day, 365 days a year through dedicated monitoring systems. Critical alerts are delivered to on-call DevOps personnel and escalated to operations management when required.
Volksign uses multiple infrastructure measures to support reliable service availability, including auto-scaling, load balancing, task queues, and rolling deployments. Database backups are performed automatically each day, and all backups are encrypted.
Volksign evaluates web application security as part of its development and release process. Vulnerability assessments include recognised web application security tools and scanning technologies that help identify potential vulnerabilities before application changes are deployed to production.
The Volksign web application uses a multi-tier architecture consisting of front-end, mid-tier, and database layers. These layers are logically separated within a DMZ configuration, providing independent boundaries between application components and limiting direct interaction between system layers. This guarantees maximum protection.
Verify signers before they access sensitive documents. Volksign provides multiple identity verification methods to add another security control to document access. Organisations can choose from four verification methods: (a) passcode verification, (b) SMS verification, (c) knowledge-based authentication (KBA), (d) ID check. These options help organisations restrict document access to verified recipients and support their security and compliance requirements.
Help us identify security issues. If you discover a potential security vulnerability affecting Volksign, please follow the Responsible Vulnerability Disclosure Process to submit your report to our Security team.
Schedule a personalised one-to-one demonstration with a Volksign product specialist.