Last updated 2026-08-04. This page describes how Docracy is built and operated today — not a substitute for a SOC 2 report or legal advice. For a marketing overview of ESIGN & UETA see ESIGN & UETA. For privacy details see Privacy; for processing terms see the DPA.
🔒 Trust & security, at a glance
Secure documents. Signatures aligned with US and EU e-signature law. Full visibility into every step.
TLS in transit; Cloudflare platform encryption at rest for documents and application data; HMAC-signed signing links that can't be guessed; production secrets never ship in the client bundle.
SES workflows designed to support the US ESIGN Act & UETA and EU eIDAS simple electronic signatures — with an optional WhatsApp-verified Advanced Electronic Signature (AES) track for paid accounts.
Every view, consent, signature, and decline is timestamped with IP, user-agent, and a content hash. Each completed chain gets a signed PDF plus a certificate of completion.
Anyone with a completed document — not just the sender or signers — can confirm it was really completed through Docracy and when, without needing an account. Verify a document.
Docracy provides simple electronic signatures (SES) with a timestamped audit trail and a certificate of completion. That model is designed to support everyday business documents under US and EU e-signature frameworks — see ESIGN & UETA below.
By default, Docracy does not verify signer identity. Anyone with a signing link can sign as the name on it. The audit trail proves what was signed and when, not who physically signed.
Signed-up accounts (free or paid) can additionally deliver a signer's link over WhatsApp instead of (or alongside) email. That link only reaches a phone number tied to that signer's own WhatsApp account, Meta's delivery/read receipts are recorded in the audit trail next to the existing tamper-evident PDF hash, and a PIN — set by the preparer and required, not optional, on every WhatsApp-delivered link — must be entered before signing, so possession of the phone alone isn't enough. Together, that combination is designed to meet the EU eIDAS criteria for an Advanced Electronic Signature (AES): a signature uniquely linked to and capable of identifying the signatory, created under their sole control, and detectably tied to the signed data. It is not a Qualified Electronic Signature (QES) — we are not a Qualified Trust Service Provider (QTSP), don't issue qualified certificates, and haven't sought third-party AES certification. For contracts that require a QES or a fully identity-verified signature, use a compliance-grade provider.
Docracy electronic signatures are designed to support the requirements of the U.S. Electronic Signatures in Global and National Commerce Act (ESIGN) and the Uniform Electronic Transactions Act (UETA) for SES-style electronic signatures. We use careful “aligned with / designed to support” language — not a certification or legal guarantee that every document type is enforceable in every jurisdiction.
Under ESIGN and UETA, electronic signatures are generally given legal effect when the parties consent to do business electronically, intend to sign, and an associated record can be retained and accurately reproduced. Docracy’s signing flow is built around those practical requirements:
This is SES-level by default. Paid and Enterprise accounts can additionally turn on WhatsApp-verified signing — the AES-track option described in What Docracy is (and isn't) above — but Docracy still does not provide QES, identity verification, or QTSP services under any plan. Suitability for a given agreement depends on document type, industry rules, and jurisdiction — this page is not legal advice.
EU note: the free-tier SES model is consistent with eIDAS simple electronic signatures for many low-stakes business documents. WhatsApp-verified signing (paid/Enterprise) is designed to meet the higher eIDAS AES bar instead — see above — but we do not claim QES under eIDAS on any plan.
Anonymous signing chains use a short retention window (default 9 days after creation; configurable up to a product maximum on paid plans). Documents and related signing state are deleted when the TTL expires — or sooner after the chain completes and final copies are emailed. Paid workspaces keep dashboard history and templates according to the account's plan until you delete them or close the account.
For each significant event (view, consent, sign, decline), we record timestamp, IP address, user-agent, and a cryptographic hash of the document content at that point. When a chain completes, parties can download a signed PDF plus a certificate of completion that summarizes that trail.
Docracy runs on Cloudflare (Workers, Pages, KV, R2, D1, and related services). Physical data centers, network edge, and many platform controls are covered by Cloudflare's own compliance program, which includes reports such as SOC 2 Type II and ISO 27001. Customers evaluating Docracy should treat that as shared-responsibility infrastructure evidence — available from Cloudflare under their usual NDA / trust portal process — not as a Docracy-issued SOC 2 or ISO certificate for the application layer.
Docracy (RELACON GmbH) does not hold its own SOC 2 or ISO 27001 attestation. We publish this page and answer questionnaires directly.
We use the following third parties to operate the service:
| Provider | Purpose | Region (typical) |
|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, compute, storage, bot protection, analytics | Global edge; config may pin EU |
| Resend, Inc. | Transactional email (invite, reminder, completion) | US / EU depending on Resend routing |
| Stripe, Inc. | Paid plan billing (card payments) | US / global Stripe regions |
| Google LLC | Optional Google Drive upload (customer-initiated) | Global |
| Dropbox, Inc. | Optional cloud connector (customer-initiated) | Global |
| Microsoft Corporation | Optional OneDrive connector (customer-initiated) | Global |
| Box, Inc. | Optional Box connector (customer-initiated) | Global |
Cloud connectors only run when a paid workspace connects them. We do not sell customer data or use advertising trackers.
We do not publish a recurring third-party penetration-test letter. We welcome responsible disclosure to founder@docracy.io.
Security or compliance questions: founder@docracy.io · Sales / Enterprise reviews: sales@docracy.io · Legal entity: Imprint