QCDS Security and Privacy Practices for Administrators and Senders

HTTPS, secure signer-link handling, provider-secret handling, read-only signer email evidence, protected attachments, historical evidence stability, and practical user-side security habits.

This guide applies to All plans and follows the accepted QC Digital Signature 2.0.7 implementation. Where older walkthrough language differs from the current interface or source behavior, use the current QCDS state as the authority.

Before You Begin

  • Capture the exact QCDS version, current Status message, Request identity, and the action that failed before changing several unrelated settings.
  • Do not include API keys, webhook signing secrets, old license keys, secure signer links, or private identity evidence in public diagnostics.
  • When possible, reproduce the problem with a small test PDF/test Contact so production data is not used as the diagnostic tool.

Step-by-Step Workflow

  1. Open Components > QC Digital Signature and the administrator tab that owns this setting or status.
  2. Record the current value/status before changing it.
  3. Apply the intended change using the current QCDS control.
  4. Save or run the provided action and read the resulting message.
  5. Verify the Status page and one representative frontend workflow before considering the change complete.

HTTPS

A Document Attachment field accepts one PNG or JPEG image from the signer. QCDS preserves the protected original and can append a readable presentation page to the Completed PDF. When “Display attachment in completed PDF” is disabled, the attachment page remains in the evidence flow but its PDF presentation is heavily pixelated/obscured and marked privacy-protected; the original protected attachment is still retained for authorized Completed Package access.

For QCDS Security and Privacy Practices for Administrators and Senders, verify this behavior using the actual object involved rather than a generic assumption. A global administrator setting, a sender-workspace preference, a reusable Template, and a sent Request have different ownership and history rules. QCDS is intentionally designed so changes for future work do not silently rewrite the evidence of an already-sent transaction.

Secure signer-link handling

A Document Attachment field accepts one PNG or JPEG image from the signer. QCDS preserves the protected original and can append a readable presentation page to the Completed PDF. When “Display attachment in completed PDF” is disabled, the attachment page remains in the evidence flow but its PDF presentation is heavily pixelated/obscured and marked privacy-protected; the original protected attachment is still retained for authorized Completed Package access.

For QCDS Security and Privacy Practices for Administrators and Senders, verify this behavior using the actual object involved rather than a generic assumption. A global administrator setting, a sender-workspace preference, a reusable Template, and a sent Request have different ownership and history rules. QCDS is intentionally designed so changes for future work do not silently rewrite the evidence of an already-sent transaction.

Provider-secret handling

A Document Attachment field accepts one PNG or JPEG image from the signer. QCDS preserves the protected original and can append a readable presentation page to the Completed PDF. When “Display attachment in completed PDF” is disabled, the attachment page remains in the evidence flow but its PDF presentation is heavily pixelated/obscured and marked privacy-protected; the original protected attachment is still retained for authorized Completed Package access.

Read-only signer email evidence

A Document Attachment field accepts one PNG or JPEG image from the signer. QCDS preserves the protected original and can append a readable presentation page to the Completed PDF. When “Display attachment in completed PDF” is disabled, the attachment page remains in the evidence flow but its PDF presentation is heavily pixelated/obscured and marked privacy-protected; the original protected attachment is still retained for authorized Completed Package access.

Protected attachments

A Document Attachment field accepts one PNG or JPEG image from the signer. QCDS preserves the protected original and can append a readable presentation page to the Completed PDF. When “Display attachment in completed PDF” is disabled, the attachment page remains in the evidence flow but its PDF presentation is heavily pixelated/obscured and marked privacy-protected; the original protected attachment is still retained for authorized Completed Package access.

How This Fits into the QCDS Workflow

Operational troubleshooting works best when the failure domain is isolated: installation/access, Scheduled Tasks, entitlement, PDF preparation, sending/mail, signer access/Identity Verification, or completion. Fix the narrow layer rather than resetting unrelated data.

When escalation is necessary, provide enough non-secret detail to reproduce the failure without sharing secure signer URLs, provider credentials, private identity media, or other protected evidence.

Verify the Result

  • A real test message leaves Joomla and arrives at the intended mailbox with the correct sender identity and format.
  • A direct follow-up test confirms the change affects future/current workflow behavior without rewriting historical sent Request evidence.

Common Mistakes to Avoid

  • Troubleshooting QCDS message content before confirming Joomla itself can send mail.
  • Editing the characters inside a supported token or translating the token name.
  • Asking signers to sign again when only final PDF generation or completion delivery failed.
  • Replacing a prior valid artifact before a regeneration attempt has been verified.

Troubleshooting

  • If the email does not arrive, test Joomla mail, check QCDS delivery history, then distinguish authentication/connection problems from a rejected recipient address.

Operational Best Practice

Test meaningful changes with controlled data before relying on them in production. Keep QCDS, Joomla mail, Scheduled Tasks, and entitlement health observable; preserve successful Requests and completed evidence; and make the smallest change that solves the actual problem. For handoff or support, record the QCDS version, relevant Request/Template reference, the exact action taken, and the visible result without including secrets.


Community Discussion

Want to compare workflows, share practical tips, or discuss how you use this QCDS feature? Visit the QC Digital Signature Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.