Security Centre

Effective date: [To be confirmed]Version: Draft 1.0

This page describes the security controls EscrowSign uses to protect your account and transactions, and the steps you can take to protect yourself.

Our security controls

Encryption

All data in transit is protected using TLS 1.2 or higher. Data at rest is encrypted using industry-standard encryption. We do not store plaintext passwords — passwords are hashed using an industry-standard algorithm. We do not store full payment card data, bank account details in plaintext, or cryptocurrency seed phrases.

Authentication

The Platform supports multi-factor authentication (MFA) and passkey authentication. We strongly recommend enabling MFA on your account. Session tokens are short-lived and invalidated on logout or device change. Suspicious login activity triggers a security alert.

Access controls

Access to your account data by Platform staff requires authentication, authorisation, and is logged. Staff access to sensitive data is subject to need-to-know controls, role separation, and audit logging. No single staff member can unilaterally perform sensitive actions such as fund release or account reinstatement.

Device and session monitoring

We monitor for unusual login patterns, new device registrations, and session anomalies. Suspicious activity may trigger an additional verification step or temporary account hold. You can view your active sessions and trusted devices in your account security settings.

Security testing

We conduct regular security assessments, penetration testing, and code reviews. [PLACEHOLDER — add details of security certifications or assessment frequency when confirmed.]

Payment instruction security

Payment and funding instructions are only displayed within your authenticated Platform workspace. We will never send payment instructions by email, phone, SMS, or any messaging application. If you receive payment instructions outside the Platform, treat them as a fraud attempt and report immediately.

Protecting your account

Use a strong, unique password

Use a password you have not used elsewhere. A strong password is at least 12 characters and includes a mix of letters, numbers, and symbols. Consider using a password manager.

Enable multi-factor authentication

MFA significantly reduces the risk of account takeover. Enable it in your account security settings. We support authenticator apps and hardware security keys.

Verify the website address

Always access the Platform directly by typing [PLACEHOLDER — domain] in your browser, or use a saved bookmark. Verify the padlock icon and that the address matches exactly. Never access the Platform through a link sent by email or message unless you initiated the request.

Be aware of phishing and impersonation

EscrowSign will never ask you to share your password, MFA codes, or identity documents by email or phone. We will never contact you requesting emergency fund transfers or asking you to bypass Platform security steps. If someone claiming to be from EscrowSign asks for any of the above, it is a scam — report it to us immediately.

Keep your contact details current

Ensure your email address and phone number are current in your account settings. We use these to alert you to security events and suspicious activity.

Report suspicious activity

If you notice any of the following, report it immediately through the security report function in your account or through the contact page:

  • Login from a device or location you do not recognise
  • Changes to your account details you did not make
  • Unexpected messages from a counterparty asking you to act urgently outside the Platform
  • Payment instructions received by email, phone, or message
  • Any request to share your account credentials with a third party

Vulnerability disclosure

If you discover a security vulnerability in the Platform, please report it responsibly to [PLACEHOLDER — security contact email]. We investigate all reports and aim to acknowledge within [PLACEHOLDER — period] business days. We do not pursue legal action against researchers acting in good faith within our responsible disclosure programme.