Security & Compliance
Built to protect what matters most
WoltSign is designed with security at every layer — from the infrastructure that hosts your data to the audit trails that protect every signed document.
Encryption
Data in transit is encrypted between your browser and WoltSign. Data at rest is encrypted using AES-256.
Access Controls
Role-based access controls ensure users can only access data they are authorized to view. Multi-factor authentication is supported.
Infrastructure
WoltSign runs on secure cloud infrastructure with redundancy, automated failover, and regular security hardening.
Monitoring
Continuous monitoring and logging of platform activity helps detect and respond to anomalies and unauthorized access attempts.
Vulnerability Management
We regularly assess our platform for vulnerabilities and apply patches and updates in a timely manner.
Audit Trails
Every signing event, document action, and authentication attempt is logged in an audit trail.
Data Encryption
All communication between your browser and WoltSign is encrypted in transit.
Data stored within WoltSign, including documents, signatures, and metadata, is encrypted at rest using AES-256 encryption. Encryption keys are managed through secure key management systems with strict access controls.
Access Control and Authentication
WoltSign enforces role-based access controls (RBAC) to ensure users can only view and interact with content they are authorized to access.
Secure authentication mechanisms are used to verify user identity. Support for multi-factor authentication (MFA) adds an additional layer of protection for accounts.
Administrative access to production systems is limited to authorized personnel and is subject to strict access logging and review.
Infrastructure Security
WoltSign operates on cloud infrastructure maintained by leading providers with established security certifications and physical data center controls.
Our infrastructure security practices include:
- Network segmentation and firewall rules
- Automated threat detection and alerting
- Regular infrastructure hardening and patching
- Redundant systems and availability controls
- Isolated environments for production and non-production systems
Audit Trails and Document Integrity
Every action taken on a document, including opens, views, signatures, and completions, is recorded in an audit trail associated with that document.
Audit records capture:
- Signer identity and email address
- Timestamp of each action
- IP address and device information
- Authentication events
These records support the legal enforceability of electronically signed documents and provide a verifiable chain of custody.
Vulnerability Management
WoltSign conducts regular security assessments of its platform, including vulnerability scanning and code-level reviews.
Identified vulnerabilities are prioritized and remediated according to their severity. Critical issues are addressed on an expedited basis.
We apply security patches and dependency updates on a regular schedule to minimize exposure to known vulnerabilities.
Incident Response
WoltSign maintains an incident response process to detect, contain, and recover from security incidents.
In the event of a security incident affecting customer data:
- Affected customers will be notified without undue delay, consistent with our obligations under applicable laws and our Data Processing Addendum.
- We will provide available information about the nature of the incident and steps taken to address it.
- We will cooperate with affected customers in their own incident response and regulatory obligations.
Payment Security
WoltSign does not store payment card information. All billing and subscription transactions are processed by PCI-compliant third-party payment processors, including DodoPayments and Razorpay. Payment data is handled directly by these processors and subject to their respective security controls and privacy policies.
Employee Access and Confidentiality
Access to customer data by WoltSign personnel is limited to what is necessary to provide and support the Services. Personnel with access to production systems are subject to:
- Confidentiality obligations
- Background screening where applicable
- Security training and awareness
- Least-privilege access principles
Your Responsibilities
Security is a shared responsibility. To protect your account and documents, we recommend:
- Using a strong, unique password for your WoltSign account
- Enabling multi-factor authentication where available
- Not sharing account credentials with others
- Reviewing account activity regularly
- Contacting us immediately at support@woltsign.com if you suspect unauthorized access to your account.
Related Policies
- Electronic signature vs digital signature for the difference between the legal concept and the cryptographic mechanism
- GDPR posture for how WoltSign handles personal data in e-signature workflows
- India DPDP posture for data processing under India's Digital Personal Data Protection Act
- Privacy Policy — How we collect and use your personal data
- Data Processing Addendum — Our obligations when processing data on your behalf
- Cookie Policy — How we use cookies on our platform
Contact Us
For security concerns, vulnerability reports, or compliance questions, please reach out to us:
WoltSign
Operated by Devkrest Technologies Private Limited
OFFICE, E-208 Ganesh Glory 11, Jagatpur Rd,
Sarkhej - Gandhinagar Hwy, near BSNL, Jagatpur,
Ahmedabad, Gujarat 382470, India
Email: support@woltsign.com