Security

How we protect every document and every signer.

Here's what actually happens behind a Revamp Sign link, in plain English. No vague promises: just the safeguards built into the product.

Signing links

A link only you can use, and only for a while.

Cryptographically signed

Every signing link carries a signature made with HMAC-SHA256 and a secret key only our servers hold. Change any part of the link and it stops working.

Built-in expiry

Signing links stop working when the agreement expires. Links to the document's pages and PDF expire after just 90 minutes.

Voided means voided

If a sender voids a document, its signing links stop working straight away.

Safe text links

Text messages carry a short, random code. The code alone doesn't open the document. It leads to a page that creates your signed link when you tap through.

Right signer, right time

When a document must be signed in order, a signer who opens their link early is told to wait. They can't sign out of turn.

Abuse protection

Signing, declining and text-link requests are rate-limited, which slows down anyone trying to guess or flood links.

Evidence

A record that can't be quietly rewritten.

If a signature is ever questioned, the record shows exactly what happened.

Append-only audit trail

Each step (sent, viewed, consented, signed, declined, completed, voided) is saved as an event with the time, IP address and browser. The app only ever adds events. It can't edit or delete them.

Certificate of completion

Every completed agreement includes a certificate listing each signer, how the link reached them (masked email or phone), and a time-stamped event log.

Fingerprinted signatures

Each signature image is recorded with a SHA-256 fingerprint, along with whether it was typed or drawn.

Verification hash

A hash of the audit record and the final PDF is stored with the agreement, so the sender can later confirm the file matches what was signed.

Consent & privacy

You agree before you sign anything.

Electronic-records consent

Before your first field, you're shown a disclosure about doing business electronically: paper copies, withdrawing consent, and what you need to view your records. Your acceptance is recorded.

Private storage

Documents are stored privately, never publicly. They're only shown through short-lived signed links.

Access tied to your private link

Your document opens only through the private, expiring link sent to your email or phone. Signing never involves logging in, so a page asking for your email password is a clear sign of a scam.

Infrastructure

Hardened domains and email.

Scammers usually attack the edges: fake sites and fake emails. So we've locked those down too.

HTTPS everywhere

Our sites load only over HTTPS. revampsign.com rejects connections older than TLS 1.2 and uses HSTS so browsers never fall back to insecure HTTP.

DNSSEC

revampsign.com's DNS answers are cryptographically signed, which helps stop attackers quietly redirecting visitors to a fake site.

Authenticated email

Email from revampsign.com is DKIM-signed and protected by a DMARC policy, so messages pretending to be us are filtered.

Security is ongoing work, and this page describes how Revamp Sign works today. If you've found a security issue, email [email protected]. For the legal side of e-signatures, see e-signature law, and for how Revamp365 handles personal data, read the privacy policy and subprocessors list.