The scope was the BeeSign Electronic Signature Platform — the system that stores, routes, signs, and seals your documents — measured against the criteria relevant to Security in TSP section 100, the AICPA Trust Services Criteria. Every applicable criterion was relevant to the system; none were carved out as not applicable.
BeeSign runs entirely on Google Cloud Platform and operates no data centers of its own. Google is treated as a carved-out subservice organization: the examination covered BeeSign's controls plus the complementary controls we assume Google provides, while Google's own controls are attested separately in its SOC 1 and SOC 2 Type II reports.
The auditor reported no system incidents that resulted from unsuitably designed controls or that significantly impaired BeeSign's ability to meet its service commitments.
Logical access
Access to production systems is granted only with a documented business reason and approval, under least privilege. Every user has a unique ID, shared accounts are prohibited, and a second authentication factor is required on every in-scope application. Access is reviewed quarterly and revoked within 24 hours of termination.
Change management
All platform code lives in version control, is tested outside production, and cannot reach the production branch without at least one independent approval. Permission to change those branch protections is restricted to a reviewed set of personnel.
Vulnerability management
Dependencies and container images are scanned continuously with Dependabot and Trivy, and critical and high findings are remediated on a risk-based schedule. Network and firewall configurations get a formal review at least annually.
Encryption and data protection
Customer documents, metadata, and signature profiles are encrypted in transit with TLS 1.2/1.3 and at rest with AES-256. Production infrastructure holding customer data is configured to refuse unauthenticated public access.
Monitoring, logging and alerting
Logs are collected and mined for metrics that surface potential security threats and unusual system activity. Alerting routes events to the responsible people, and every identified event is tracked through to resolution.
Incident response
Confirmed incidents are documented and driven to closure under a written Security Incident Response Plan, with a lessons-learned write-up feeding fixes back into policy. The plan is rehearsed in an annual tabletop exercise.
People and governance
A Security Steering Committee meets quarterly. Personnel acknowledge the Code of Conduct and security policies, pass background checks where local law permits, and complete security awareness training on hire and annually thereafter.
Risk and vendor management
Management runs a formal risk assessment at least annually against a maintained risk register. Vendor agreements carry security requirements, and compliance reports for high-risk vendors are collected and reviewed annually.