Encrypted in transit
Every connection to BeeSign — from your browser, your signers' phones, or the API — is protected with a minimum of TLS 1.2, earning an A+ rating from Qualys SSL Labs. Documents never travel over the wire unencrypted.
Contracts, medical forms, and financial agreements deserve more than a password. BeeSign encrypts every document in transit and at rest, verifies who's signing, and seals the result with a tamper-evident audit trail.
From the moment a document is uploaded to long after it's signed, it stays encrypted.
Every connection to BeeSign — from your browser, your signers' phones, or the API — is protected with a minimum of TLS 1.2, earning an A+ rating from Qualys SSL Labs. Documents never travel over the wire unencrypted.
Documents, templates, forms, and completion certificates are stored with 256-bit AES encryption on Google Cloud infrastructure, with signer secrets additionally encrypted at the application layer.
Completed documents are cryptographically sealed and paired with a certificate of completion, so any modification after signing is detectable.
With bring-your-own-cloud (BYOC), your organization's documents and certificates are stored in storage buckets you own — so sensitive files never leave your infrastructure.
Our transport security isn't just a claim you have to take on faith. Qualys SSL Labs — the independent, industry-standard TLS auditor — grades beesign.net an A+, the highest rating it awards. We enforce a minimum of TLS 1.2 and support the latest TLS 1.3.
The top grade from Qualys SSL Labs — the independent industry standard for TLS server testing.
Older, weaker protocol versions are refused. Every connection uses TLS 1.2 or newer, with no exceptions.
The newest, fastest, and most secure version of TLS is enabled for modern browsers and clients.
HTTP Strict Transport Security tells browsers to always connect over encrypted HTTPS — downgrade attacks are blocked.


Choose the level of signer assurance each document needs — from email verification to full biometric identity checks.
Require signers to confirm a code sent to their phone before they can open the document.
Signing links are unique, single-purpose, and tied to the recipient's email address.
Add time-based one-time passwords from any authenticator app for repeat signers who need stronger assurance.
Government ID capture, biometric face matching with liveness detection, and database validation — for signatures where you need to know exactly who signed.
The moment every recipient has signed, BeeSign takes the completed document's cryptographic fingerprint — its SHA-256 hash — and anchors it to the Bitcoin blockchain using OpenTimestamps. The result is an independent, decentralized proof that the document existed in exactly that form at that point in time.
Because the timestamp lives on a public blockchain, its integrity doesn't depend on BeeSign, on any single company, or on any server staying online. Anyone — a court, an auditor, a counterparty — can verify it independently, forever. And because only the hash ever leaves your account, your document itself stays private.
If a single byte of the document is ever altered, its hash no longer matches the blockchain record — making post-signing tampering mathematically detectable.
Security isn't a single feature — it's how the platform is built. BeeSign runs on Google Cloud and applies defense in depth across storage, access, and every link we send.
Have a security question or need details for a vendor review? We're happy to walk through our architecture.
Start your 7-day free trial — every plan includes encryption in transit and at rest, audit trails, and signer verification.