SECURITY

Document security

Encryption in transit and at rest, two-factor authentication, IP access controls, single sign-on, and US/EU data residency - everything your legal and IT teams need to say yes.

Security posture
Mutual NDA
Checking…
AES-256 encryption at rest
TLS 1.2+ in transit
Two-factor authentication
IP allowlist
Compliant & secure by designESIGNUETAeIDASHIPAA-eligible BAAGDPR DPAAES-256 · TLS 1.2+

Encrypted everywhere

AES-256 at rest, TLS 1.2+ in transit.

Two-factor authentication

TOTP for every account, with recovery codes.

IP access controls

Restrict access to allowed IP ranges.

Data residency

Keep your data in the US or the EU.

ENCRYPTION

Encrypted everywhere

Documents are encrypted in transit with TLS 1.2+ and at rest with AES-256, with daily encrypted backups and an append-only audit log behind them.

  • AES-256 at rest - Every file encrypted on disk
  • TLS 1.2+ in transit - Encrypted on the wire, end to end
  • Daily encrypted backups - Durable, encrypted, and tested
  • Append-only audit log - Records can be added, never altered
Encrypted storage · Mutual NDA
Encryption
Mutual NDA.pdf
protecting your file
In transit
TLS 1.2+
At rest
AES-256
Daily encrypted backups
ACCOUNT 2FA

Two-factor authentication

Protect the accounts behind your documents. Members enroll TOTP from any authenticator app, keep recovery codes for backup, and admins can require it for the whole workspace.

  • Authenticator app - TOTP via Authy, Google Authenticator, 1Password, and more
  • Recovery codes - One-time backup codes generated at setup
  • Workspace enforcement - Admins can require 2FA for everyone
app.documentesign.com/login
Two-factor authentication
Enter your authenticator code
6-digit code from your authenticator app
Verify
Lost your device? Use a recovery code
ACCESS CONTROL

Access control

Decide exactly who can reach your workspace. Restrict access to specific IP ranges, assign roles, and connect your identity provider for single sign-on and automated provisioning.

  • IP allowlist - Restrict access to CIDR ranges; admins keep an escape hatch
  • Roles & permissions - Owner, Admin, Manager, and Member scopes
  • Single sign-on - SAML 2.0 and OIDC for enterprise teams
  • SCIM provisioning - Auto-provision and deprovision from your IdP
app.documentesign.com/settings/security
IP allowlist
Allowed IP ranges
203.0.113.0/24allowed
10.0.0.0/8allowed
Workspace admins always keep access
DATA CONTROL

Your data, your control

Keep your data in the US or the EU, export any document and its certificate at any time, and know your documents are never used to train models or deleted without you.

  • Data residency - Store your data in the US or the EU
  • Never trains models - Your documents are never used to train AI
  • No automatic deletion - Documents stay until you remove them
  • Export anytime - Download any PDF and its audit certificate
app.documentesign.com/settings/data
Data residency
Store our data in
US
United States
EU
European Union
Never used to train models
No automatic deletion
Export any document anytime
THE WHOLE TOOLKIT

All the signing tools you need, in one place.

Document eSign gives you the complete toolkit to prepare, send, sign, manage, and audit documents with confidence.

22+ tools

Core signing

Route, send, and sign - sequential or parallel, with the controls demanding workflows need.

Sequential & parallel routingApprovers, viewers & CCAutomatic remindersScheduled sendIn-person signing (tablet)Redirect on completionCustom disclaimer noticeDocument expiry
3+ tools

Fields & forms

Capture far more than a signature, with validation enforced before a document can complete.

Standard field libraryCustom fields (conditional, validation)Signer attachmentsDraw / type / upload signatures
4+ tools

Templating & bulk send

Prepare a document once, reuse it forever, and send to hundreds from a single CSV.

Unlimited templatesShared team templatesPublic template share linksBulk send (CSV)
15+ tools

Security & audit

Identity controls at the bar your IT team sets, plus a tamper-evident record on every document.

Workspace 2FA enforcementIP restrictionsSSO + SCIMMultiple workspacesDocument sending policiesCertificate of completionSHA-256 + PAdES-B sealAppend-only audit trailAutomatic document deletionESIGN · UETA · eIDAS
6+ tools

Branding

Your logo, colour, sending domain, and signing page - your brand from first email to final seal.

Custom branding (logo + color)Custom email sending domainEmail template customizationBYO signing domain
6+ tools

Integrations & AI

Connect the storage and tools you already run on, plus practical, privacy-respecting AI.

Drive · Dropbox · OneDriveAutomatic cloud backupSlack notificationsAI assist
AUDIT-GRADE BY DEFAULT

Every document, verifiable and built to last.

A SHA-256 hash, an embedded PAdES-B signature, and a complete audit trail on every signed envelope - the proof your legal and IT teams need to say yes.

Start free, no card
Tamper-evident seal
PAdES-B signature, verifiable in any PDF reader.
Complete audit trail
IP, device, geolocation, and auth method on every event.
See how the audit trail works
FAQ

Common questions.

How is my data encrypted?

Documents are encrypted in transit with TLS 1.2+ and at rest with AES-256. Backups are encrypted too, and the audit log is append-only.

Do you support two-factor authentication?

Yes. Anyone can enable TOTP two-factor authentication from any authenticator app, with one-time recovery codes generated at setup. Admins can require 2FA across the whole workspace.

Can I restrict access by IP address?

Yes. Add the IP ranges (in CIDR notation) that are allowed to reach your workspace; requests from outside them are blocked. Workspace admins always keep an escape hatch so you can't lock yourself out.

Do you support single sign-on and SCIM?

Yes - SAML 2.0 and OIDC single sign-on, plus SCIM 2.0 provisioning, are available for enterprise teams. Reach out through the contact page and we'll set it up.

Where is my data stored?

You can keep your data in the United States or the European Union. Documents, audit logs, and backups stay in your chosen region.

Do you use my documents to train AI models?

No. Your documents are never used to train models. AI features only act on a document when you ask them to.

Will my documents ever be auto-deleted?

No. Documents stay in your workspace until you remove them, and you can export any PDF and its audit certificate at any time.

Can I get a HIPAA Business Associate Agreement?

Yes, a HIPAA-eligible BAA is available for healthcare teams. Reach out through the contact page and we'll set it up.

Live in under a minute

Ready to try it?

Create your free forever account, upload a document, and send it for signature in minutes. No credit card required.

Unlimited envelopes on Free Legally binding · global Audit trail on every document