Security

Your documents, protected at every step.

Contracts, medical forms, and financial agreements deserve more than a password. BeeSign encrypts every document in transit and at rest, verifies who's signing, and seals the result with a tamper-evident audit trail.

Security at a glance

  • A+ Qualys SSL Labs rating, TLS 1.2 minimum
  • 256-bit AES encryption at rest
  • OTP, TOTP, and biometric signer verification
  • Tamper-evident audit trail on every document
  • Blockchain timestamp proof anchored to Bitcoin
  • Optional bring-your-own-cloud storage

Encryption at every layer

From the moment a document is uploaded to long after it's signed, it stays encrypted.

Encrypted in transit

Every connection to BeeSign — from your browser, your signers' phones, or the API — is protected with a minimum of TLS 1.2, earning an A+ rating from Qualys SSL Labs. Documents never travel over the wire unencrypted.

Encrypted at rest

Documents, templates, forms, and completion certificates are stored with 256-bit AES encryption on Google Cloud infrastructure, with signer secrets additionally encrypted at the application layer.

Tamper-evident sealing

Completed documents are cryptographically sealed and paired with a certificate of completion, so any modification after signing is detectable.

Your cloud, if you want it

With bring-your-own-cloud (BYOC), your organization's documents and certificates are stored in storage buckets you own — so sensitive files never leave your infrastructure.

A+ SSL Labs Rating

Independently rated A+ for SSL/TLS

Our transport security isn't just a claim you have to take on faith. Qualys SSL Labs — the independent, industry-standard TLS auditor — grades beesign.net an A+, the highest rating it awards. We enforce a minimum of TLS 1.2 and support the latest TLS 1.3.

A+ overall rating

The top grade from Qualys SSL Labs — the independent industry standard for TLS server testing.

TLS 1.2 enforced

Older, weaker protocol versions are refused. Every connection uses TLS 1.2 or newer, with no exceptions.

TLS 1.3 supported

The newest, fastest, and most secure version of TLS is enabled for modern browsers and clients.

HSTS enabled

HTTP Strict Transport Security tells browsers to always connect over encrypted HTTPS — downgrade attacks are blocked.

Qualys SSL Labs summary report for beesign.net showing an A+ overall rating, TLS 1.3 support, and HSTS enabled
Qualys SSL Labs report showing an A+ grade across every beesign.net server

Know exactly who signed

Choose the level of signer assurance each document needs — from email verification to full biometric identity checks.

SMS one-time passcodes

Require signers to confirm a code sent to their phone before they can open the document.

Email verification

Signing links are unique, single-purpose, and tied to the recipient's email address.

Authenticator apps (TOTP)

Add time-based one-time passwords from any authenticator app for repeat signers who need stronger assurance.

Full identity verification

Government ID capture, biometric face matching with liveness detection, and database validation — for signatures where you need to know exactly who signed.

Blockchain timestamping

Proof of when it was signed — that you don't have to trust us for

The moment every recipient has signed, BeeSign takes the completed document's cryptographic fingerprint — its SHA-256 hash — and anchors it to the Bitcoin blockchain using OpenTimestamps. The result is an independent, decentralized proof that the document existed in exactly that form at that point in time.

Because the timestamp lives on a public blockchain, its integrity doesn't depend on BeeSign, on any single company, or on any server staying online. Anyone — a court, an auditor, a counterparty — can verify it independently, forever. And because only the hash ever leaves your account, your document itself stays private.

If a single byte of the document is ever altered, its hash no longer matches the blockchain record — making post-signing tampering mathematically detectable.

How the proof works

  • The signed document is reduced to a unique SHA-256 hash
  • Only that hash — never the document — is submitted to the OpenTimestamps calendars
  • The hash is committed to the Bitcoin blockchain and confirmed by its block
  • A portable proof file is stored alongside the document for independent verification
  • Verifiable by anyone, with no account and no trust in BeeSign required

Security practices that hold up

Security isn't a single feature — it's how the platform is built. BeeSign runs on Google Cloud and applies defense in depth across storage, access, and every link we send.

Have a security question or need details for a vendor review? We're happy to walk through our architecture.

  • Access to your workspace is isolated per user and per organization — members of the same team can't see each other's private documents
  • Signing and approval links use signed, expiring tokens — they can't be guessed or reused for other documents
  • Download links are short-lived signed URLs that expire automatically
  • Soft-deleted documents are archived, not silently destroyed, so accidental deletions are recoverable
  • Signer TOTP secrets are encrypted before they're ever stored
  • Every send, view, signature, and approval is logged with timestamp and IP address
  • Completed documents are hash-anchored to the Bitcoin blockchain for an independent, tamper-proof timestamp

Sign securely from day one

Start your 7-day free trial — every plan includes encryption in transit and at rest, audit trails, and signer verification.