Security
A signed agreement is evidence. XDocs treats it that way.
The point of a signature is that somebody can rely on it later. This page says what XDocs records, what it protects, and — just as plainly — what it does not do yet.
The record
- Frozen at sendSending snapshots the document. What a signer agrees to is that copy, and later edits to the draft can never change it.
- Consent before inputA versioned electronic-records disclosure is shown unticked. Acceptance is recorded with timestamp, IP address and disclosure version before any field accepts a value.
- Integrity digestsA SHA-256 digest of the document and another of the completed record are printed on the certificate, and can be recomputed from the stored rows to detect any later change.
- Append-only audit trailEvery view, signature, decline, reminder and void is recorded with its time, actor and IP address, and carried on the certificate of completion.
Who can see what
- Gates per linkPassword, email capture, six-digit email verification, allow and block lists, domain restrictions, expiry, view caps, an NDA before viewing, and download control — set independently on every link.
- Watermarks that name the readerComposed per link from the reader's email, the date, time, IP and link, and stamped on downloaded copies as well as the screen.
- Roles, guests, SSO and SCIMFour ranked roles; guests narrowed to named rooms on every path, not only the ones buttons lead to; SAML single sign-on and SCIM provisioning on the Business plan.
- Access codes and failed attemptsA signer can be asked for a code shared out of band. Failed attempts are logged, and the assistant can say which gate turned a visitor away.
ESIGN and UETA
The US ESIGN Act (15 U.S.C. § 7001) and UETA ask four things of an electronic signature. All four are implemented.
- Intent to sign
- An explicit confirmation before any signature is applied.
- Consent to transact electronically
- A versioned disclosure covering paper copies, withdrawal, scope, hardware and software, contact updates and retention.
- Association with the record
- Fields live in the document body and freeze with it; each value is hashed into the completion digest.
- Record retention
- The signed PDF with its certificate is archived on completion and emailed to every party.
Under the product
- API keys are stored hashed and carry only the scopes you choose, with per-key rate limits.
- Share-link passwords are stored hashed; we only ever compare them.
- Credentials for connected services — Slack, HubSpot, Salesforce — are encrypted with AES-256-GCM.
- Webhook deliveries are signed, so your endpoint can verify they came from XDocs.
- A custom link domain serves the document viewer and nothing else; every other path is a 404.
- Actions the assistant proposes are approved with a server-signed token that cannot be forged from the browser.
- Mail forwarded into a workspace is treated as content to report on, never as instructions to follow.
What is not here yet
XDocs does not currently offer PAdES or PKI certificate signing, eIDAS advanced or qualified signatures, 21 CFR Part 11 controls, or HIPAA controls, and it does not hold a SOC 2 report. If your agreement needs one of these, XDocs is not the right tool for it today.
You can also run XDocs yourself, in Docker against your own Postgres, so every row it writes stays in a database you control.
Security questions or a report: hello@xdocs.io
One place for every important document.
Create, sign, share and understand your documents with XDocs.

