πŸš€ NEW: sproof's AI assistant for quick integration Learn more

Security & Compliance


πŸ’‘ At a Glance

sproof Sign is a secure and legally compliant e-signature solution specially for European companies:

  • GDPR-compliant: No reliance on US services or third-country providers

  • eIDAS-compliant: Legally valid electronic signatures according to EU requirements

  • ISO/IEC 27001 certified: Audited information security management

  • Traceable and audit-proof signature processes according to European standards

Group-626077.png

1. Legally valid signing with sproof Sign

sproof Sign supports all European signature standards for secure and transparent signing processes – 100% legally compliant according to the eIDAS regulation including full control and traceability.

eIDAS-compliant (Regulation No. 910/2014): EU regulation that governs electronic signatures and trust services in 30 EU and EEA states.

ZertES-compliant: Swiss law that sets the requirements for electronic signatures and trust services at the national level.

FDA 21 CFR Part 11-compliant: Regulation that governs electronic records and signatures in regulated industries such as pharmaceuticals and medical devices.


2. Information Security

Security and data protection are central pillars of sproof Sign – developed for companies with the highest compliance and regulatory requirements.

  • ISO 27001 certified

  • Focus on companies with the highest compliance requirements (finance, healthcare, public administration and critical infrastructure)

  • Security and data protection strategy as an integral part of the platform

  • Ensuring IT security and regulatory compliance


3. Data Protection

sproof Sign guarantees the highest data protection standards – fully GDPR-compliant, with true data sovereignty and transparent infrastructure.

  • 100% compliant with the GDPR

  • Data processing agreement (DPA) according to EU standard

  • Deletion and retention policies in accordance with the strictest data protection requirements

  • Protection against insider threats and unauthorized access

  • Exclusively European data centers – no US subsidiaries,
    no third-country connections

  • All subcontractors are subject exclusively to European law

Last updated: