Security
EscrowSign is built with security by design. Every layer of the platform is designed to protect your identity, funds, and transaction data.
Multi-factor authentication
Enable MFA on your account to require a one-time code in addition to your password when signing in.
Passkeys
Use a device passkey for passwordless sign-in. Passkeys are phishing-resistant and tied to your specific device.
Password safety
Use a unique, strong password for EscrowSign. We store only a secure hash — never your plaintext password.
Phishing protection
Check the domain is the official EscrowSign domain before entering credentials. We will never send you a sign-in link unless you requested it.
Official domains
Only access EscrowSign from our official domain. Bookmark it. Do not follow links from emails or messages.
Bank-detail verification
Payment instructions are shown only inside your authenticated dashboard. Never transfer funds based on details received by email, phone, or message.
Device and session management
Review your active sessions in your account settings. Remove any session you do not recognise.
Incident reporting
If you suspect your account has been compromised, contact support immediately through the official website. Change your password and revoke all sessions.
Platform security architecture
EscrowSign employs TLS for all data in transit, encryption at rest, role-based access control with least-privilege principles, dual control for sensitive operations, immutable audit records, web application firewall, rate limiting, and regular penetration testing. We do not store plaintext passwords, full card data, or crypto seed phrases. Identity documents are not visible to counterparties. Security architecture details are not publicly disclosed to protect platform integrity.
