Skip to main content

Electronic Signature Compliance

Documenso provides legally valid electronic signatures that comply with major electronic signature regulations worldwide.

Regulatory Compliance Status

RegulationStatusDescription
ESIGN / UETACompliantU.S. federal and state electronic signature laws
eIDAS SESCompliantEU Simple Electronic Signatures
eIDAS AESPlannedEU Advanced Electronic Signatures
eIDAS QESPlannedEU Qualified Electronic Signatures
ZertESPlannedSwiss federal electronic signature law
Documenso cryptographically seals all signed documents to prevent any alterations after signing, regardless of signature level.

What This Means for You


Data Protection & Privacy

Documenso takes data protection seriously and implements measures to comply with GDPR and other privacy regulations.

GDPR Compliance


Security Practices

Documenso implements security best practices throughout the development and deployment lifecycle.

Development Security

  • Code review: All changes require review before merging
  • Dependency scanning: Automated monitoring for vulnerabilities
  • Static analysis: Security scanning in CI/CD pipeline
  • Open source: Publicly auditable codebase at github.com/documenso/documenso

Infrastructure Security (Documenso Cloud)

LayerImplementation
HostingEU data centers with SOC 2 compliance
NetworkTLS 1.2+ for all connections
DatabaseManaged PostgreSQL with automated encrypted backups
StorageEncrypted object storage for documents
Monitoring24/7 infrastructure monitoring and alerting
UpdatesRegular security patches applied to all infrastructure

Cryptographic Protection


Industry Certifications

Documenso maintains or is working toward various industry certifications and compliance frameworks.
CertificationStatusDescription
SOC 2CompliantSecurity, availability, and confidentiality controls
21 CFR Part 11Compliant (Enterprise)FDA electronic records and signatures
ISO 27001PlannedInformation security management system
HIPAAPlannedHealthcare data protection
SOC 2 reports are available at documen.so/trust.
See Certifications for detailed information about each framework.

Technical Standards

Documenso implements industry-standard cryptographic and archival technologies.

Implemented Standards

  • ISO 32000 - PDF digital signature specification
  • X.509 - Certificate format for digital signatures
  • RFC 3161 - Timestamping protocol for long-term validity
  • PDF/A - Archival format for long-term document preservation

Standards in Development

  • PAdES - PDF Advanced Electronic Signatures (ETSI EN 319 142)
  • XAdES - XML Advanced Electronic Signatures
See Standards for technical details.

Audit & Verification

Audit Trails

Every document maintains a complete audit trail recording:
EventRecorded Data
Document creationTimestamp, creator identity
Recipient additionRecipient details, assigned fields
Document sentTimestamp, delivery method
Document viewedTimestamp, viewer identity, IP address
Field completedTimestamp, field type, signer identity
Document completedTimestamp, final document hash
Audit trails provide evidence of the signing process, including who signed, when they signed, and the sequence of events.

Signature Verification

Signed documents can be verified to ensure:
  • Document has not been altered since signing
  • Signature was created with a valid certificate
  • Timestamp proves when the document was signed
PDF readers can verify signatures directly without requiring Documenso.

Self-Hosting for Enhanced Compliance

Self-hosting Documenso provides additional control for compliance-sensitive deployments:

Benefits for Compliance

See the Self-Hosting Guide for deployment options.

Vulnerability Disclosure

Documenso operates a responsible disclosure process for security vulnerabilities.

Reporting a Vulnerability

If you discover a security vulnerability, please report it to: [email protected] Include:
  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fixes (optional)

Response Timeline

StageTimeline
AcknowledgmentWithin 48 hours
Initial triageWithin 5 days
Status updateWithin 10 days
Resolution targetDepends on severity
Do not publicly disclose vulnerabilities until they have been addressed. Public disclosure of unpatched vulnerabilities puts users at risk.

Limitations & Disclaimers

What Documenso Does Not Provide

CapabilityStatus
Qualified Electronic Signatures (QES)Not supported; requires QTSP integration
Advanced Electronic Signatures (AES)Partial; full AES requires identity verification
Identity Verification (KYC)Not built-in; may require third-party integration
Qualified CertificatesNot issued; would require QTSP accreditation
Industry-Specific ComplianceFeatures depend on configuration and license
This documentation is provided for informational purposes only and does not constitute legal advice. Compliance requirements vary based on jurisdiction, document type, industry regulations, and specific circumstances.
Consult qualified legal counsel to:
  • Determine appropriate signature levels for your documents
  • Understand your compliance obligations
  • Assess whether electronic signatures are valid for your use case
  • Draft appropriate disclosures and privacy notices

Compliance Topics

Security & Policies

Technical Documentation

Build docs developers (and LLMs) love