Security

EscrowSign is built with security by design. Every layer of the platform is designed to protect your identity, funds, and transaction data.

Multi-factor authentication

Enable MFA on your account to require a one-time code in addition to your password when signing in.

Passkeys

Use a device passkey for passwordless sign-in. Passkeys are phishing-resistant and tied to your specific device.

Password safety

Use a unique, strong password for EscrowSign. We store only a secure hash — never your plaintext password.

Phishing protection

Check the domain is the official EscrowSign domain before entering credentials. We will never send you a sign-in link unless you requested it.

Official domains

Only access EscrowSign from our official domain. Bookmark it. Do not follow links from emails or messages.

Bank-detail verification

Payment instructions are shown only inside your authenticated dashboard. Never transfer funds based on details received by email, phone, or message.

Device and session management

Review your active sessions in your account settings. Remove any session you do not recognise.

Incident reporting

If you suspect your account has been compromised, contact support immediately through the official website. Change your password and revoke all sessions.

Platform security architecture

EscrowSign employs TLS for all data in transit, encryption at rest, role-based access control with least-privilege principles, dual control for sensitive operations, immutable audit records, web application firewall, rate limiting, and regular penetration testing. We do not store plaintext passwords, full card data, or crypto seed phrases. Identity documents are not visible to counterparties. Security architecture details are not publicly disclosed to protect platform integrity.