Trust

Your clients trust you with the most consequential paperwork of their lives. We don't take that lightly. This page is the short version of how Peekop protects verified access, live workflow visibility, and evidence-backed completion. Verified Access is the point where the intended recipient confirms the email tied to the signing request and enters the protected signing session. The full technical breakdown lives on our security page.

No account required does not mean anonymous signing. Peekop uses recipient-specific links and exact recipient email verification before protected signing actions are allowed.

For the public-language signer verification model, read How Peekop Verifies Signers Without Accounts. For the direct misconception check, read Can Anyone With a Peekop Link Sign?.

Request Journey Evidence

Verified Access is visible before viewed, Signing Started, and signed

Peekop request journey showing Sent, Verified Access, Viewed, Signing Started, and Signed.

Controlled Lifecycle

Recipient-Specific Link to Completion Record, with control along the way

Recipient-Specific Link->Verified Access->Electronic Consent->Protected Signing Session->Signed->Completion Record->Link Closed
  • Link access alone is not signing authority.
  • Exact recipient email verification is required before protected signing actions.
  • Senders can void access before completion, and expiration windows limit how long links remain valid.
  • After completion, the signing link no longer opens another signing session.

Verified access before signing

A Peekop link alone is not signing authority. Exact recipient email verification is required before protected signing actions begin.

Read the technical detail ->

Completion evidence stays attached

Verified Access, signing activity, integrity checks, and completion artifacts stay connected to the request through the Completion Record.

Read the technical detail ->

Links expire

Signing links carry a built-in expiration date you choose. Stale links don't work. Voided links stop working immediately.

Read the technical detail ->

Evidence across the request journey

Verified access, signing activity, and completion evidence stay attached to the request so the signed outcome is backed by more than a final file.

Read the technical detail ->

Workflow controls, not vague promises

Trust comes from recipient verification, protected signing sessions, expiration, revocation, and structured completion evidence.

Read the technical detail ->

Controlled lifecycle after signing

After completion, the signing link no longer opens another signing session, while the signed outcome remains backed by evidence and artifacts.

Read the technical detail ->

What we're honest about

Most security pages overpromise. Here's what Peekop is and isn't today, in plain language:

We are early.

We are not yet SOC 2 certified. That audit is on our 2026 roadmap once we cross 25 paying customers. Until then, we document our controls in detail and we'll complete a security questionnaire (SIG Lite, CAIQ) for any vendor review on request.

We are not a HIPAA service.

Peekop does not sign Business Associate Agreements today. If you need to send documents containing protected health information regulated by HIPAA, please use a HIPAA-covered signing tool until we ship that capability.

We are not a notary.

Some forms require a notary's seal regardless of how the signature is captured. Peekop will get the signature on the page, but we are not a Remote Online Notarization service and don't pretend to be one.

We tell you when we change things.

Whenever we add a new service that touches your documents (a new email provider, a new analytics tool), we email every customer at least 30 days before the change. You always know the full list of services that touch your data.

Need a deeper review?

If you're a compliance officer, broker-dealer, or a carrier evaluating Peekop for vendor approval, we want to make this easy. Email security@peekop.com and tell us what your team needs - questionnaire, call, or just a sit-down with the engineer who wrote the code. We respond within one business day.