Policies & attestation

Publish your security policies, distribute them for review, and collect versioned e-signature attestations — audit-ready evidence for frameworks like ISO 27001 (A.5.1) and SOC 2 (CC2.2). Employees sign from a no-login link, and you always know who's signed and who hasn't.

Create a policy

  1. Go to Policies in the main navigation.
  2. Create a policy from scratch, or adopt one of the built-in templates.
    • Templates are offered by country, so you're shown the ones relevant to your organisation. Adopt a single template or use adopt all to seed a starter set in one click.
  3. Set whether the policy requires a signature (attestation) or is informational only.

Each policy is versioned. When you change the text, signatures are tracked against the version that was current when the person signed, so re-publishing correctly asks people to re-attest.

Publish & distribute

Publish a policy, then notify the people who need to review and sign it. Distribution is by email, and you choose who receives it:

TargetWho gets it
AllEvery active user in your organisation
GroupActive members of a chosen group
DepartmentActive users whose department matches
Specific usersA hand-picked list

Each recipient gets a single-use, no-login signing link. They open it, read the policy, type their name to attest, and they're done — no account or password required.

Track attestation

Open a policy to see its signature roster:

  • Who has signed and who hasn't, with a live counter that refreshes on its own.
  • Remind unsigned — re-send the request to only the people who haven't signed the current version yet (a "remind only the not-yet-signed" nudge), rather than spamming everyone.

Branding on the signing page

If you've uploaded an org logo and turned on Show logo on policies, your logo appears on the public signing page and on policy emails, so the attestation looks like it came from your company. See Branding.

Signed evidence — every attestation records the signer, the policy version, and a timestamp. Export it alongside your other reports when auditors ask for proof.


Next: Reports & compliance.