ELECTRONIC SIGNATURE FOR ENTERPRISE

Electronic signature for enterprise.

SSO, SCIM, US/EU data residency, BYO signing domain, full whitelabel, and a dedicated account manager. A custom contract scoped to your organization - not a one-size SaaS plan.

SSO
SAML · OIDC
SCIM 2.0
Auto-provisioning
Whitelabel
Your brand
US · EU
Data residency
WHY ENTERPRISE

Electronic signature built for enterprise security.

Identity that lives where your IdP lives. Documents that stay where your DPO needs them. A custom contract that procurement will actually approve.

SSO & SCIM

SAML 2.0 and OIDC. SCIM 2.0 for auto-provisioning. Tested against Okta, Azure AD, Google Workspace, Auth0, OneLogin.

Authentication

Data residency

Pick US (Virginia) or EU (Frankfurt). Documents, audit logs, backups stay in your region. Dedicated infrastructure.

Security

BYO signing domain

Host the signing page at sign.yourcompany.com. We provision the SSL certificate. Signers never see ours.

Branding

BYOK · BYO certificate

Customer-managed encryption keys via AWS KMS. Optional BYO PKI for PAdES signatures sealed with your own org cert.

Crypto detail

Full whitelabel

Zero "Powered by" footprint anywhere - emails, signing page, audit certificate. Your brand, end to end.

Whitelabel

Reliable infrastructure

Dedicated, monitored infrastructure with encrypted backups and a published status page for incident visibility.

Reliability

Your documents stay put

Nothing is auto-deleted. Signed envelopes stay in your workspace until you remove them, mirrored to your own cloud backup for extra durability.

Document storage

Dedicated account manager

A named contact who knows your workspace, joins quarterly business reviews, and is your escalation path for everything.

2-hour response · business hours
WHAT'S INCLUDED

The complete enterprise electronic signature toolkit.

Every capability in Document eSign, plus the identity, residency, whitelabel, and reliability layer that enterprise IT, security, and procurement sign off on.

Identity & access

Plug signing into your IdP and govern every seat the way your security team requires.

SSO (SAML 2.0 & OIDC)SCIM 2.0 provisioningIP allowlist (CIDR)Workspace 2FA enforcementMultiple workspacesSession controls

Core signing & routing

Route, send, and sign in any order, with the workflow controls demanding teams need.

Sequential & parallel routingApprovers, viewers & CCAutomatic remindersScheduled sendIn-person signingDocument expiry

Fields, templates & bulk send

Capture far more than a signature, then reuse it forever and send to thousands at once.

Standard & custom fieldsValidation rulesSigner attachmentsUnlimited & shared templatesPublic share linksBulk send (CSV)

Branding & whitelabel

Your logo, domain, and signing page - a fully whitelabeled experience from first email to final seal.

Custom logo & colorCustom sending domainBYO signing domainFull whitelabel (no Powered-by)Per-workspace brandingEmail template customization

Data residency & encryption

Keep documents in the region you choose, encrypted with keys you control.

US or EU data residencyDedicated infrastructureBYOK (AWS KMS)AES-256 · TLS 1.2+Automatic document deletionNo AI model training

Audit, reliability & support

A tamper-evident record on every document, with a named contact behind it.

Certificate of completionSHA-256 + PAdES-B sealBYO signing certificateAppend-only audit trailPublished status pageDedicated account manager
ENGAGEMENT

From scoping call to live in 14 days.

Most enterprise customers go from first call to first signed envelope in about two weeks.

  1. 1

    Scoping call

    30 minutes with sales engineering. Seats, regions, integrations, and security requirements. We propose pricing within 48 hours.

  2. 2

    Security review

    Standard questionnaire (CAIQ-lite), pen test summary, DPA, sub-processor list, architecture walkthrough on request.

  3. 3

    Contracting

    Custom MSA, DPA, and order form. Annual term, paid by invoice or wire. Most cycles close in 1-2 weeks of legal review.

  4. 4

    Implementation

    SSO & SCIM wired up, BYO domain & cert provisioned, audit policy configured, templates migrated. Live in 5-10 business days.

SECURITY POSTURE

Enterprise security and compliance.

No certifications hand-waving. Just the controls, the architecture, and the audit trail.

Encryption
· AES-256-GCM at rest
· TLS 1.3 in transit (1.2 floor)
· HSTS preload
· Annual key rotation
· BYOK via AWS KMS
Signature integrity
· SHA-256 document hash
· PAdES-B-LT embedded
· Independent TSA timestamp
· Verifiable in Adobe Acrobat
· Optional BYO certificate
Audit & ops
· Append-only audit log
· Public status page
· Quarterly DR drills
· Encrypted, regional backups
· Responsible disclosure program

A note on certifications. Document eSign is early in its formal certification program. We don't have a SOC 2 Type II report yet; we have a clear path and a target audit window. We can share our DPA, sub-processor list, security posture documentation, pen test summary, and architecture review. The signatures themselves are legally binding under the ESIGN Act and UETA in the US and the EU's eIDAS regulation, independent of any certification timeline. For most enterprises this is enough to start; for the few where a SOC 2 letter is a hard gate, we'll let you know upfront so we don't waste your time.

FAQ

Enterprise - FAQ

How does enterprise e-signature pricing work?

Enterprise pricing is custom and scoped to your organization rather than a fixed per-seat list price. It is built from the variables that actually drive cost: the number of seats, your document volume, how many regions you need, and the specific capabilities you turn on, such as SSO, SCIM, data residency, BYOK, or full whitelabel. Most engagements are annual and paid by invoice or wire rather than a credit card. The process is quick: a 30-minute scoping call with sales engineering establishes the footprint, and we send a written proposal with pricing within 48 hours. There is no obligation to that call, and you get a concrete number to take to procurement rather than a range.

What does Enterprise include that the Business plan does not?

Enterprise adds the controls that a security, IT, and procurement team require before rolling an e-signature tool out organization-wide. On top of everything in Business, you get single sign-on over SAML 2.0 and OIDC, SCIM 2.0 auto-provisioning, a bring-your-own signing domain (sign.yourcompany.com) with the SSL certificate we provision, an optional bring-your-own signing certificate for PAdES seals, full whitelabel with zero "Powered by" footprint anywhere, US or EU data residency, customer-managed encryption keys through AWS KMS, a dedicated account manager, and a custom contract. In short, Business is a complete product for a team, and Enterprise wraps it in the identity, residency, branding, and contractual guarantees a large organization needs.

How long does enterprise onboarding take?

Most enterprise customers go from first call to first signed envelope in about two weeks. That window covers a security review, MSA and DPA negotiation, SSO and SCIM integration with your identity provider, custom signing-domain and certificate provisioning, and audit-policy configuration. The technical implementation itself - wiring up SSO and SCIM, provisioning the domain and certificate, and migrating templates - typically lands in five to ten business days. Larger or more heavily regulated rollouts, or ones that need extended legal review or a deeper architecture assessment, can extend to roughly six to eight weeks. We give you a realistic timeline during scoping so the date you commit to internally is one we can actually hit.

Do you have SOC 2 or other security certifications?

We are early in our formal certification program and do not have a SOC 2 Type II report yet, and we would rather tell you that plainly than imply otherwise. What we can share today is substantial: our DPA, our sub-processor list, security posture documentation, a penetration-test summary, and an architecture review on request. We have a defined path and a target audit window for SOC 2. For HIPAA, contact sales for the current BAA timeline. For most enterprises this evidence is enough to start, and for the few where a completed SOC 2 letter is a hard, non-negotiable gate, we will say so upfront so we do not waste your evaluation time.

Can we negotiate the MSA and DPA?

Yes. We maintain a baseline MSA and DPA that most legal teams accept with light edits, and we are genuinely flexible on terms wherever a change does not compromise the security posture or the operational model that keeps the service reliable. You are not handed a take-it-or-leave-it click-through agreement. In practice, most legal cycles close within one to two weeks of review, because the starting documents are already written to be reasonable for a large buyer. Your dedicated account manager and our team stay in the loop through redlines so questions get answered quickly rather than bouncing between inboxes, which is usually what keeps a contract from closing on time.

How does data residency work in practice?

Once you select a region - US (Virginia) or EU (Frankfurt) - your documents, audit logs, and backups stay in that region and never leave it. The selection is enforced at the infrastructure level on dedicated, monitored infrastructure, not just a setting. Customer-managed encryption keys can be scoped regionally through AWS KMS, so the keys protecting EU data live in the EU. For organizations that operate across regions, residency can be selected at the workspace level, so one part of the business can sign in the EU while another signs in the US under the same account. This is how teams meet GDPR and internal data-handling requirements without standing up a separate tool per region.

Are e-signatures legally binding for an enterprise rollout?

Yes. Documents signed with Document eSign are legally binding under the U.S. ESIGN Act of 2000 and state UETA laws, and under the EU's eIDAS regulation, which give an electronic signature the same standing as wet ink when intent, consent, attribution, and a retained record are present. Every signed document is sealed with a SHA-256 hash and a PAdES-B-LT signature carrying an independent TSA timestamp, verifiable in Adobe Acrobat, and optionally sealed with your own organization's certificate. Each one ships with a certificate of completion recording every signer's email, IP address, and timestamp on an append-only audit log. That gives a large organization defensible, court-ready evidence at scale, which is exactly what legal and compliance teams ask for before standardizing on a signing platform.

NEXT STEP

Talk to sales.

30 minutes. We'll scope seats, regions, integrations, security. You'll have a custom proposal in your inbox within 48 hours.

30-min scoping call
Custom proposal in 48h
Security review on request
Live in about two weeks
Or email sales@documentesign.com directly