GDPR β Compliant
Processing under GDPR with data minimization. Data processing agreement and subprocessor list available.
SigID is in pre-launch. Pilot customers get direct engineering and security contact.
Join the pilot programTrust Center
How we protect your data, which standards we meet, what's on the roadmap. Fully open, verifiable any time.

Processing under GDPR with data minimization. Data processing agreement and subprocessor list available.
Audit trail, incident response paths and 24/72-hour notification obligations supported.
Information Security Management System under construction. Pre-audit planned for H2 2026.
SOC 2 audit planned after US market entry.
Cloud Computing Compliance Criteria Catalogue as a long-term target.
Authentication via FIDO2 and WebAuthn. TOTP as 2FA backup. No SMS-TAN as a high security level.
Key material stays on the device. libsodium algorithms, no custom crypto.
Row Level Security in PostgreSQL plus application layer. Tenant IDs on every row.
Append-only Audit Events. Audit-IDs for external re-verification.
Fingerprints instead of full documents. PDFs can be deleted after verification.
SigID runs on Hetzner in Germany. Data and keys never leave the EU.

Full audit trail
Append-only Audit Events. Audit-IDs for external re-verification.
Security architecture
Append-only Audit Events. Audit-IDs for external re-verification.
How SigID reacts to security incidents.