Complete guide
ESIGN Act & UETA, EU eIDAS (SES / AES / QES), GDPR, security architecture, SOC 2, and pricing — explained in plain English, with links to the deep-dive page for each topic.
Last updated 2026-08-12. This page is a plain-English overview, not legal advice — whether a given document and signing method is enforceable depends on the document type, industry rules, and jurisdiction involved.
An electronic signature is any electronic sound, symbol, or process attached to a record that a person uses to sign it — a typed name, a drawn signature, a click on "I agree," or a cryptographically-verified action. Electronic signature law generally recognizes three tiers of strength, most clearly defined in the EU's eIDAS regulation but used informally worldwide:
Which tier you need depends on the document and jurisdiction — a freelance contract usually needs nothing beyond SES; a small number of document types (certain real estate transfers, wills, court filings) require more, or aren't eligible for electronic signature at all in some jurisdictions. See our dedicated page on whether electronic signatures are legally valid for the caveats. Ready to actually make one? See how to create a digital signature.
In the United States, two laws give electronic signatures legal effect: the federal Electronic Signatures in Global and National Commerce Act (ESIGN, 2000) and the Uniform Electronic Transactions Act (UETA), adopted by most states. Together they hold that an electronic signature or record can't be denied legal effect just because it's electronic, as long as:
Docracy's signing flow is built around exactly those three requirements: signers check a consent acknowledgment before signing, the signing action itself is logged as the intent event, and every document ships with a timestamped audit trail, a signed PDF, and a certificate of completion. For the full walkthrough — including how each requirement maps to a specific step in the product — see our dedicated ESIGN Act & UETA guide.
The EU's eIDAS regulation is what defines the SES / AES / QES tiers described above, and gives each of them legal effect across EU member states. Docracy's free and paid tiers use the SES model by default — timestamped consent, intent, and a tamper-evident audit trail, without identity verification — which is consistent with eIDAS simple electronic signatures for most everyday business documents.
For signers who need a stronger tier, Docracy offers WhatsApp-verified signing for paid and Enterprise accounts: a signer's link is delivered only to a phone number tied to their own WhatsApp account, with a required PIN before signing. That combination is designed to meet the eIDAS criteria for an Advanced Electronic Signature (AES). It is not a Qualified Electronic Signature — Docracy is not a Qualified Trust Service Provider (QTSP), doesn't issue qualified certificates, and hasn't sought third-party AES certification. For agreements that specifically require QES, use a compliance-grade QTSP provider instead.
More detail: WhatsApp-verified signing · Advanced Electronic Signature (AES) · full trust & security posture
We don't make a blanket "GDPR-compliant" claim — that phrase means little without specifics, since compliance depends on how a customer configures and uses a tool as well as the tool itself. What Docracy does provide:
We will notify affected account holders without undue delay if we become aware of a personal-data breach affecting their workspace, consistent with GDPR Art. 33/34 where they apply.
Every document view, consent, signature, and decline is timestamped with IP address, user-agent, and a cryptographic hash of the document content at that moment. Traffic runs over TLS; signing links are HMAC-signed tokens rather than guessable account passwords; document bytes and application state live on Cloudflare's platform (R2, KV, and D1), encrypted at rest by Cloudflare's own platform defaults. When a signing chain completes, every party receives the signed PDF plus a certificate of completion summarizing the full audit trail.
On SOC 2 and ISO 27001 specifically — these are independent audits that verify an organization's security controls over time. Cloudflare, the infrastructure Docracy runs on, maintains SOC 2 Type II and ISO 27001 reports covering the physical data centers, network edge, and platform controls we build on. Docracy (RELACON GmbH) does not hold its own SOC 2 or ISO 27001 attestation for the application layer today — we publish our full security questionnaire answers directly instead. Treat the Cloudflare reports as shared-responsibility infrastructure evidence, available under Cloudflare's own NDA/trust-portal process, not as a Docracy-issued certificate.
Full breakdown — encryption, access control, retention, subprocessors, and a complete security questionnaire — on the Trust & security page.
Not every business needs the same thing. A few factors worth weighing before you commit to a tool or a plan:
Per-seat pricing punishes teams as they grow. A flat monthly rate for unlimited signers and team members scales better for most small businesses.
Most contracts only need SES. Don't pay for QES-grade identity verification if your documents don't require it — and don't settle for SES if they do.
A reviewed, ready-to-use template saves more time than any editor feature. Check whether templates are actually reviewed for legal clarity, not just pre-formatted.
If you only send a handful of documents a year, a tool that requires an account just to try it adds friction you don't need.
See how Docracy compares to specific providers: DocuSign · eversign · HelloSign · PandaDoc · Adobe Sign
Full feature breakdown on the pricing page.
Docracy's template library covers NDAs, service agreements, contractor agreements, W-9 and I-9 forms, and more — free to use, with no account required. These are general-purpose starting points, not tailored legal advice for your specific agreement, industry, or jurisdiction.
Popular starting points: Mutual NDA · Independent contractor agreement · W-9 form · I-9 form
By industry: Small business · Freelancers · Real estate · HR
Generally, yes. In the United States, the ESIGN Act and UETA give electronic signatures the same legal standing as ink signatures for most business documents, provided the parties consented to sign electronically, intended to sign, and the record can be retained and reproduced. In the EU, eIDAS gives legal effect to electronic signatures at three tiers — SES, AES, and QES (see below) — with the appropriate tier depending on what the document requires. Some document types (wills, certain real estate transfers, court filings) are excluded or have extra requirements in many jurisdictions — check with counsel for anything high-stakes.
These are the three tiers of electronic signature defined by the EU's eIDAS regulation (and used informally elsewhere too). A Simple Electronic Signature (SES) is any electronic indication of intent to sign — typing a name, clicking to agree, drawing a signature — with no built-in identity verification. An Advanced Electronic Signature (AES) must be uniquely linked to the signer, capable of identifying them, created under their sole control, and detectably tied to the signed data. A Qualified Electronic Signature (QES) is an AES created with a qualified signature-creation device and backed by a qualified certificate issued by a licensed Qualified Trust Service Provider (QTSP) — it's the highest tier and carries the strongest legal presumption.
Not by default. Anyone holding a Docracy signing link can sign as the name on it — the platform records what was signed and when, not a verified identity check on who physically clicked. Paid and Enterprise accounts can add a required PIN to a signing link, and can deliver that link over WhatsApp so it only reaches a phone number tied to that signer's own WhatsApp account — together those are designed to meet the EU eIDAS bar for an Advanced Electronic Signature (AES), but Docracy is not a Qualified Trust Service Provider and does not issue QES. Full detail on our exact posture is on the Trust & security page.
We don't make a blanket "GDPR-compliant" claim — no vendor honestly can, since compliance depends on how a customer configures and uses a tool, not just the tool itself. What we do offer: a standard Art. 28 GDPR Data Processing Agreement for paid and account use, a published list of named subprocessors with their typical processing regions, and a short default retention window (9 days) for anonymous signing chains so documents don't linger longer than needed. See the DPA and the Trust & security page for the specifics.
Docracy (built and operated by RELACON GmbH) does not hold its own SOC 2 or ISO 27001 attestation today. The infrastructure Docracy runs on — Cloudflare Workers, Pages, KV, R2, and D1 — is covered by Cloudflare's own compliance program, which includes SOC 2 Type II and ISO 27001 reports. That's shared-responsibility infrastructure evidence, not a Docracy-issued certificate for the application layer. We publish our full security questionnaire answers on the Trust & security page instead of a report.
Yes — that's the default Docracy flow. Upload a document, add signers and fields, and send; each signer gets a link, signs in their browser, and everyone receives the completed, signed PDF plus a certificate of completion by email. No account, password, or credit card required for the free tier.
Anonymous signing chains (the free, no-signup flow) use a short retention window — 9 days after creation by default — after which the document and its signing state are deleted, or sooner once the chain completes and final copies are emailed out. Paid workspaces keep dashboard history and templates according to their plan until deleted or the account is closed.
Free: $0, no account or card required, up to 2 signers per document. Paid: $10/month flat — not per seat — for unlimited signers, a team dashboard, reusable templates, bulk send, a 90-day signing window, embedded signing, webhooks, an MCP connector, AI drafting/review tools, white-labeling, PIN-protected links, and cloud storage connectors. Enterprise: custom pricing for invoice billing, annual contracts, SLA support, and SSO/multi-workspace setups. Full breakdown on the pricing page.
Related reading: What is an NDA? · Are electronic signatures legally valid? · ESIGN Act & UETA · Trust & security
Ready to send your first document?
Sign a document free