Access control
Access control
Account holders and signers access Golo Sign through controlled authentication, optional multi-factor verification, and permission-based workflows.
Access to Golo Sign is restricted to authenticated users and invited signers. We combine account protections, optional multi-factor authentication, and signing-session controls so that only the right people can view or complete assigned documents.
Account security
Users must maintain account security, keep login credentials confidential, and notify us of any unauthorised access or security breach. Users are responsible for all activities conducted through their account.
- Strong password requirements for sender accounts
- Secure session management across dashboard access
- Email verification for account registration and recovery
- Account activity tied to verified contact details
- Prompt notification expected for suspected compromise
If you believe your account has been accessed without authorisation, contact [email protected] immediately.
Multi-factor authentication
Account holders may enable multi-factor authentication for an additional layer of protection beyond a password. We recommend enabling MFA for teams handling sensitive or high-value agreements.
- Optional MFA for sender accounts
- Compatible with standard authenticator applications
- Backup codes available for account recovery
- Additional verification required at login when MFA is enabled
- Recommended for administrators and frequent senders
Signer access
Recipients access assigned documents through secure signing sessions. Additional verification may be required before a signature is completed, depending on sender configuration.
- Individual signing sessions per recipient
- Access limited to assigned documents and roles
- Optional verification steps before signing
- Branded signing experience within the Golo Sign platform
- Voided or completed documents restrict further access as appropriate
User responsibilities
Security is shared. While Golo Sign implements platform controls, users must take reasonable steps to protect their credentials and devices.
- Protect passwords and enable MFA where available
- Do not share login credentials with unauthorised persons
- Report suspicious activity promptly
- Maintain secure devices and up-to-date software
- Ensure only authorised staff access sender accounts
Violation of acceptable use or security requirements may result in suspension or termination of access.
Questions about security?
For security reviews, vendor questionnaires, or compliance discussions, contact our team. We can provide additional detail relevant to your organisation.
Australian Owned & Operated
AES-256 Encryption
Electronic Transactions Act Ready
Audit Trails & Logging
Multi-Factor Authentication