Secure Infrastructure for Your Document Workflows
Your contracts and signed documents are important. Indigo e-Sign is built with security controls across document storage, access, authentication, and signing workflows to help protect the information you use on the platform.
Cloud Infrastructure
Indigo e-Sign uses cloud-based infrastructure and storage services to operate the platform reliably at scale.
Our Privacy Policy identifies AWS, Google Cloud, and other cloud hosting and infrastructure providers as part of the services used to operate and store information on the platform.
This cloud-based approach supports the document management, signing, and related services provided through Indigo e-Sign, ensuring high availability and global responsiveness.
Redundant cloud microservices maintain continuous document accessibility, data backups, and low-latency processing.
Protecting Data in Transit and at Rest
Security starts with protecting information while it moves through the platform and while it is stored. These measures help protect documents and other information handled through Indigo e-Sign.
All data in motion between signers, review engines, and our infrastructure is secured with modern HTTPS and TLS encryption.
Stored contract files, audit records, and metadata are encrypted on server drives with bank-grade 256-bit encryption.
Third-party cloud storage connectors handle authorization tokens with specialized encryption and key rotation.
Controlled Access to Documents
Not everyone should have access to every document. Indigo e-Sign uses role-based access controls and authentication to help control access to information within the platform.
For signing sessions, participants receive unique, secure, time-limited access tokens. This allows invited participants to access their signing sessions without requiring them to create an Indigo e-Sign account.
Organization administrators configure team permissions so team members only view and act on contracts relevant to their department or authorization tier.
Secure Authentication
Indigo e-Sign uses several measures to protect account and signing access. These controls are designed to help prevent unauthorized access and automated attacks.
Cryptographically signed access tokens isolate signer sessions and prevent URL enumeration.
Granular organizational permission structures ensure strict document visibility and editing boundaries.
Server-level security middleware validates sessions, filters malicious requests, and blocks unauthorized route traversals.
Time-sensitive one-time passcodes verify participant identity during sensitive login and sign-up flows.
Intelligent bot-detection filters defend registration, login, and signature portals against automated abuse.
User passwords are salted and hashed using Django's PBKDF2 algorithm, never stored in plain text.
Cloud Storage Integrations
Indigo e-Sign can connect with supported cloud storage services including Google Drive, Dropbox, and Microsoft OneDrive.
When you connect one of these services, Indigo e-Sign uses OAuth tokens to access your files on your behalf. These tokens are encrypted and stored securely.
You can disconnect an integration and revoke its access at any time, immediately removing cached credentials and severing synchronization.
Monitoring and Security Updates
Indigo e-Sign's security measures include role-based access controls and monitoring, along with regular security audits and updates.
Automated monitoring systems keep watch over server performance, API request limits, and anomalous access behaviors.
Security is treated as an ongoing part of operating the platform rather than a one-time setup. Our engineers perform routine dependency patching and vulnerability scans.
Infrastructure for eSignature and APIs
Indigo e-Sign provides both a browser-based signing platform and REST APIs for businesses that want to integrate electronic signatures into their own applications.
- Document Signing Workflows & Signer Routing: Programmatically create, dispatch, and order signature stages.
- Reusable Document Templates: Deploy reusable contracts and pre-tagged signature fields via API.
- Real-Time Webhooks: Instant automated notifications for events such as viewed, signed, and completed documents.
- Sandbox & API Keys: Test end-to-end signing in an isolated developer sandbox environment.
Infrastructure and Document Security
Infrastructure security works together with the other security controls available across Indigo e-Sign. This gives businesses a connected approach to protecting documents throughout the signing workflow.
Infrastructure FAQs
Built to Support Secure Document Workflows
Indigo e-Sign brings document management, electronic signatures, audit trails, and AI-powered document review together in one platform. Our infrastructure and security controls are designed to help businesses manage their documents and signing workflows with confidence.