Skip to content
bSignBY BINARIUM
Features Security Integrations Healthcare Pricing FAQ
Sign in
Features Security Integrations Healthcare Pricing FAQ Sign in
Trust

Security and compliance

Where your documents live, how bSign proves who signed them, the controls you have, and the laws electronic signatures rely on. Last updated September 28, 2026.

On this page Where documents live Signing in and access Knowing who signed The evidence Signing on paper Privacy controls Controls for administrators Is it legally binding? Health and personal information What we don't claim Reporting a security problem

Where documents live

Documents, signatures and signing records are stored in Canada, on servers operated by Binarium, an IT services company in Ontario. The EU recognizes Canada as protecting personal data adequately. Every connection to bSign, the app and the signing pages, is encrypted over HTTPS.

Each organization's documents are kept apart from every other's. IT providers and multi-location practices can run a separate site for each client or location, each with its own users, settings and records.

Signing in and access

  • Microsoft 365 and Google sign-in for staff, or a password with two-step verification from an authenticator app.
  • Invitations, not shared passwords. New people get an email invitation and choose how they sign in. A password an administrator resets is temporary: it has to be changed at the next sign-in.
  • Roles. Administrators manage the site; users see their own documents. Administrators are emailed when someone new joins their site.
  • Connected accounts. The tokens for a connected OneDrive, SharePoint or Google Drive are stored encrypted, and can be disconnected at any time.

Knowing who signed

  • A personal link for each signer, which stops working when the document expires or is voided.
  • A one-time code emailed to the signer before the document opens, on any document or on every document a site sends.
  • In person: someone who signs on the sender's device is recorded as signing in person, hosted by the sender.
  • Passing it on: if a signer hands a document to a colleague, both names and the reason are in its history.
  • Consent first: before signing, each signer agrees to the Electronic Record and Signature Disclosure, which explains how to withdraw consent and get a paper copy.
  • A review before signing: signers are guided through their fields, required ones first, and see what they're signing with before it goes in.

The evidence

Every finished document comes with proof of how it was signed:

  • A sealed PDF. The signed PDF is digitally sealed with a certificate, so any later change shows up in Adobe Acrobat or any PDF reader that checks signatures. Its SHA-256 fingerprint is recorded when the document is finished.
  • A certificate of completion, itself sealed: each signer's name and email, when they viewed and signed, their IP address and its approximate location, and how they were verified.
  • A full history that can only be added to: sent, viewed, signed, reminded, corrected, passed on, declined or voided, with who, when and from where.
  • Name and date under each signature. Signatures carry the signer's name and the date beneath them, inside their box, so a printed copy still shows who signed and when.
  • What each signature means. A site can ask every signer why they're signing (they approve the document, have reviewed it, wrote it, agree to its terms, or are a witness); the answer is on the certificate and in the history.

Signing on paper

Where a sender allows it, someone who'd rather use a pen can Print & sign: they download their copy with their boxes marked, sign it by hand and upload a scan or photos. bSign adds the scan to the end of the document after a cover page that says who uploaded it and when, records each file's SHA-256 fingerprint in the audit trail and on the certificate, seals the document as usual, and tells the sender so they can look the scan over.

Privacy controls

  • Send links only: emails carry a link and a one-time code, never the document itself, so nothing sits in an inbox to be forwarded.
  • Retention: choose how long finished documents are kept; bSign deletes them for good when the time is up.
  • Recycle bin: a deleted document waits 30 days before it's gone, so a mistake is easy to undo.
  • Deleting a site: an administrator can delete their whole site; it's kept for 15 days in case that was a mistake, then deleted for good.
  • Access log: who opened, downloaded, printed or shared each document, including our own staff, ready to export.
  • Your data, on request: see, correct, export or delete personal information; see our privacy policy.

Controls for administrators

  • Users, roles and invitations; turning off someone's access; resetting a password or two-step verification.
  • Branding on every signing page and email, and signing links on your own web address.
  • Whether signers may Print & sign, whether they're asked why they're signing, and how the date under signatures is written.
  • For IT providers: a site per client, usage per site, and splitting or merging sites, which both sides have to approve.
  • API tokens and webhooks for your own systems.

Is it legally binding?

Yes, for most documents. Electronic signatures are recognized in:

  • Canada: PIPEDA (Part 2) and the provincial electronic commerce acts, such as Ontario's Electronic Commerce Act, 2000.
  • The United States: the ESIGN Act and the Uniform Electronic Transactions Act (UETA), adopted by nearly every state.
  • The European Union: eIDAS, which says an electronic signature can't be refused as evidence just because it's electronic.
  • The United Kingdom: the Electronic Communications Act 2000 and UK eIDAS.

Some documents can still need ink or a witness, such as wills, some powers of attorney and some real-estate filings. The rules differ from place to place: check with your advisor when it matters.

Health and personal information

Clinics and other teams handling sensitive information can turn on Send links only, set a retention period and review the access log. We sign a HIPAA business associate agreement, a GDPR data processing agreement or a PHIPA service-provider agreement on request, and share our privacy impact and threat-risk assessments and breach response procedure in the compliance pack.

What we don't claim

bSign isn't certified under SOC 2 or ISO 27001. It doesn't make qualified electronic signatures (QES) under eIDAS, and it hasn't been validated for FDA 21 CFR Part 11. If your work needs one of these, talk to us before you rely on bSign for it; we'll tell you plainly what fits.

Reporting a security problem

If you think you've found a security problem in bSign, email support@binarium.ca with what you found and how to see it. Please don't access other people's data or disrupt the service while you look. We reply to every report.

© 2026 Binarium. All rights reserved.support@binarium.ca Made in Ontario, Canada