SignSealShip Partner API · Trust Center
Signsealship Trust Center
Trust center
SignSealShip Partner API maintains a public trust center documenting count, named, and note compliance.
notarizationremote online notarizationelectronic signaturedocument verificationlegal technologyreal estatetitle and escrowshipping
Certifications & Compliance
countnamednote
Source
Trust Center
generated: '2026-09-01'
method: searched
source: https://signsealship.com/security
docs: https://signsealship.com/security
probed: '2026-09-01'
http_status: 200
trust_center:
published: true
url: https://signsealship.com/security
title: Security & Trust
self_description: Trust center
linked_as: Linked as "Trust Center" in the site header and footer navigation
certifications:
count: 0
named: []
note: >-
NO CERTIFICATIONS ARE HELD OR CLAIMED. This is recorded as a genuine zero, not as a gap in
our reading. The page publishes an explicit "honest table" of what is and is not built,
headed "If it isn't marked 'built in' here, we don't claim it anywhere."
honest_table:
- item: ESIGN Act (15 U.S.C. 7001)
status: built in
detail: >-
Consent captured per 101(c) before any signing; signatures attributed to identified signers;
records retained and reproducible.
- item: UETA
status: built in
detail: Intent, attribution and record integrity handled by the signing flow and audit trail.
- item: Tamper-evident sealing (CMS / PKCS#7)
status: built in
detail: >-
Every sealed PDF carries a cryptographic signature verifiable in Adobe Acrobat with no
SignSealShip account.
- item: SHA-256 tamper-evident audit trail
status: built in
detail: Append-only event log per envelope; each event chains to the previous one.
- item: RON state rules
status: built in
detail: >-
Deterministic state-and-document rules checked before payment; restricted combinations are
refused.
- item: SOC 2 Type II
status: on roadmap
detail: >-
"Not yet certified, and we won't imply otherwise." No date is claimed pending an auditor.
- item: ISO 27001
status: not certified
detail: '"We don''t hold this certification and don''t claim it."'
controls_published:
document_integrity: >-
Asymmetric signing key held in Google Cloud KMS; the private key never leaves Google's
infrastructure. A hash of the finished PDF is signed and the CMS (PKCS#7) signature is
embedded covering the PDF ByteRange, so a single changed byte visibly breaks the seal in any
standards-compliant validator -- verifiable on the reader's own machine.
audit_trail: >-
Append-only event log; each event carries the SHA-256 of the event before it. CONSENT /
VIEWED / SIGNED / SEALED events recorded in UTC with originating IP.
identity_verification: >-
Knowledge-based authentication from public records plus government-ID credential analysis,
then a live state-commissioned notary on camera. RON available through notaries in 43
jurisdictions.
encryption: >-
TLS on every path in transit; encrypted at rest on Google Cloud. Customer document buckets
block all public access; signing links expire 24 hours after issue; time-limited signed URLs
used only where a delivery rail requires them.
retention: Sealed documents kept in a dedicated 7-year retention bucket.
infrastructure: >-
Cloud Run, Cloud SQL (managed PostgreSQL) and Cloud KMS. Each deployed service runs under its
own dedicated service account with least-privilege access. Secrets mounted from a managed
secret store, never baked into images. Deploys ship by immutable image digest with the source
commit verifiable at https://signsealship.com/api/version.
edge: >-
Cloudflare in front of public /api/* traffic with an origin shared-secret check and rate
limits on every public write.
inbound_webhooks: >-
Fail closed -- every inbound vendor event must pass signature verification, and if a vendor's
verification is not configured its route does not exist in production.
data_handling: >-
Uploads are malware-scanned (event-driven ClamAV) and DLP-classified with category names only
-- never content -- in logs.
subprocessors:
published: true
disclosure_level: by role, not by name
named_directly:
- Google Cloud Platform
- Stripe
by_role:
- Remote online notarization network partner
- Shipping API partner (USPS, UPS, FedEx labels and tracking)
- Print-and-mail fulfillment partner
- Transactional email provider
note: >-
Business customers can request the fully named subprocessor list under a data-processing
agreement. Partial naming is a real limitation for a vendor-review process, and the page says
so rather than hiding it.
verifiability_claim: >-
The distinguishing posture of this trust center is that its central security claim is
independently checkable by the reader without trusting the vendor: open a sealed PDF in free
Adobe Reader and inspect the signature panel. Very few trust centers of any size offer a
reader-executable proof in place of a badge.
gaps:
- No SOC 2, ISO 27001 or any third-party attestation.
- No named subprocessor list without a DPA.
- No /.well-known/security.txt -- see security/signsealship-vulnerability-disclosure.yml.
- No penetration-test summary or architecture attestation published.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/signsealship-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.