When the documents are shared on the web with other users, it's important to upscale the security levels to prevent fraudulent attempts and bad actors from compromising your document security. SigningHub provides you with three methods that can be configured for either individual or all recipients collectively:
Access duration - to allow document access only for a specified duration
Access authentication - to authenticate the recipient through a specified password, a One-Time Password or a Time-based One-Time Password when attempting to access the document
Signing authentication - to authenticate the recipient through a One-Time Password or a Time-based One-Time Password when attempting to sign the document
In case the authentication/validation fails in any of the above scenarios, the recipient will be restricted from accessing/signing the document. By default, these document security features are disabled for a new workflow. You can always enable them as required before sharing.
Access duration
Select the check box to allow document access only for a specified duration for the selected or all recipients. You can specify the access duration via a specific date and time or a number of days. On enabling the toggle shown in the image below, the following options will be displayed:
Based on dates Set a specific form and till date/time for a recipient to access the document. The recipient will not be able to access the document beyond this duration. If the document is not processed within the specified time, the document will be considered declined.
Based on days Set a number of days in which a recipient can sign the document after receiving it. The recipient will not be able to access the document after this duration. Also if the document is not processed within the specified days, the document will be considered declined.
Access authentication
Enable the toggle to enable recipient authentication through a specified password or an OTP when attempting to access the document. The following options will be displayed:
Shared password Set a password that the recipient would need to provide in order to access the document. While typing in a password, the Password Policy will be displayed. SigningHub will allow you to specify a password that complies with the given Password Policy. Password Policy will be configured at the Enterprise level or Administrator level according to account type.
One-Time Password (SMS & Email) This option will let the document owner send an OTP to the recipient that will used for recipient authentication. Whenever the recipient tries to open this document an OTP will be sent to the recipient's email, mobile number, or both depending upon the document owner's service plan configuration. When the service plan allows "SMS OTP", a field to specify the mobile number of a recipient to send an OTP will be displayed. The document will be accessible only upon providing the correct OTP. By default, the specified number is displayed partially masked to comply with the GDPR policy. Click the 'Eye' icon to view the complete number.
Time-based One-Time Password This authentication option will let the recipient access the document after they have entered the Time-based One-Time Password. Whenever the recipient tries to open this document they will be prompted to enter the Time-based One-Time Password from the authenticator app configured on their mobile device. In case the recipient has not configured two-factor authentication (2FA), upon trying to access a document that requires Time time-based One-Time Password, they will be prompted with a 'Configure Two Factor Authentication' dialogue to set up and provide a Time-based One-Time Password. The document will be accessible only upon providing the correct Time-based One-Time Password.
Signing authentication
Enable this option to enable recipient authentication through the OTP process when attempting to sign the document. On enabling the toggle shown in the image below, the following options will be displayed:
One-Time Password (SMS & Email) This option will let the document owner send an OTP to the recipient that will used to sign authentication. Whenever the recipient tries to sign this document an OTP will be sent to the recipient's email, mobile number, or both depending upon the document owner's service plan configuration. When the service plan allows "SMS OTP", a field to specify the mobile number of a recipient to send an OTP will be displayed. The document will be signed only upon providing the correct OTP. By default, the specified number is displayed partially masked to comply with the GDPR policy. Click the 'Eye' icon to view the complete number.
Time-based one-time password This authentication option will let the recipient sign the document after they have entered the Time-based One-Time Password. Whenever the recipient tries to sign this document, they will be prompted to enter the Time-based One-Time Password from the authenticator app configured on their mobile device. In case the recipient has not configured two-factor authentication (2FA), upon trying to sign a document that requires Time-based One Time Password, they will be prompted with a 'Configure Two Factor Authentication' dialogue to set up and provide a Time-based One-Time Password. The document will be signed only upon providing the correct Time-based One-Time Password.
Save
Click to save the information entered on the dialog.
Cancel
Click to discard the information entered on the dialog.
Considering the screenshot scenario, the document will be accessible only from October 31, 2024, 12:57:00 to November 08, 2024, 12:57:00 for processing. The document will be considered declined if it is not processed within this period.
Considering the screenshot scenario, the document will be accessible for the next 10 days after receiving it. The document will be considered declined if it is not processed within this period.
Considering the screenshot scenario, the recipient will have to provide this (specified) password to access and process the document.
Considering the screenshot scenario, an OTP will be sent to the email address and specified mobile number of recipient, whenever he attempts to access the document. He must provide the received OTP to access and process the document.
Considering the screenshot scenario, the recipient will be prompted to provide the Time-based One-Time Password whenever they attempt to access the document.
Considering the screenshot scenario, an OTP will be sent to the email address and specified mobile number of recipient, whenever he attempts to sign the document. He must provide the received OTP to sign the document.
Considering the screenshot scenario, the recipient will be prompted to provide the Time-based One-Time Password whenever they attempt to sign the document.