Skip to content
Agree.Solutions

Security & compliance

Designed to support ESIGN and UETA workflows with a clear audit trail.

How does Agree.Solutions secure documents?

Uploaded and completed documents are stored on a private disk and served only through authorized, time-limited links. Signers reach a document through a signed URL backed by a hashed token that expires and is rate-limited. SHA-256 hashes of the original and completed files make changes detectable, every event is logged with IP, user agent, and timestamp, and platform admins have no blanket access to customer documents.

How your documents are protected

These are the controls behind every signature. For the legal side of the same story — what ESIGN and UETA ask for, and what we deliberately do not claim — see our compliance position.

Private document storage

Uploaded originals and completed documents are stored on a private disk and served only through authorized, time-limited links — never a predictable public path.

Secure signer links

Signers receive a signed URL backed by a hashed token. Only the hash is stored; tokens expire and are rate-limited.

Tamper-evident hashing

We record SHA-256 hashes of the original and completed documents so changes are detectable.

Complete audit trail

Every meaningful event — viewed, started, field completed, signed, completed — is logged with IP, user agent, and timestamp, and summarized on the certificate of completion.

Least-privilege access

Documents belong to organizations. Platform admins do not have blanket access to customer document contents.

Honest about compliance
Agree.Solutions is designed to support ESIGN and UETA workflows and offers HIPAA-ready architecture for qualified plans after a BAA review. We do not claim SOC 2 certification or guaranteed legal enforceability.

Security questions

Is Agree.Solutions SOC 2 certified?

No. We do not claim SOC 2 certification, and we would rather say so than imply an audit we have not completed. What we do have is described on this page: private storage, hashed and expiring signer links, SHA-256 hashing, and per-event audit logging.

Can Agree.Solutions staff read my documents?

Documents belong to your organization. Platform admins do not have blanket access to customer document contents.

How are signer links protected?

Each signer gets a signed URL backed by a token that is only stored as a hash. Tokens expire and requests are rate-limited, so an expired or guessed link stops working.

How would I know if a signed document had been altered?

We record SHA-256 hashes of the original and the completed document. Re-hashing a copy and comparing it against the recorded hash makes any change to the file detectable.

Is Agree.Solutions HIPAA compliant?

The architecture is built to support a HIPAA workflow for qualified plans after a BAA review. We do not represent the product as HIPAA compliant until that review is complete.