Trust & security

Last updated 2026-08-04. This page describes how Docracy is built and operated today — not a substitute for a SOC 2 report or legal advice. For a marketing overview of ESIGN & UETA see ESIGN & UETA. For privacy details see Privacy; for processing terms see the DPA.

🔒 Trust & security, at a glance

Secure documents. Signatures aligned with US and EU e-signature law. Full visibility into every step.

End-to-end security

TLS in transit; Cloudflare platform encryption at rest for documents and application data; HMAC-signed signing links that can't be guessed; production secrets never ship in the client bundle.

Legally-aligned signatures

SES workflows designed to support the US ESIGN Act & UETA and EU eIDAS simple electronic signatures — with an optional WhatsApp-verified Advanced Electronic Signature (AES) track for paid accounts.

Full transparency & control

Every view, consent, signature, and decline is timestamped with IP, user-agent, and a content hash. Each completed chain gets a signed PDF plus a certificate of completion.

Independently verifiable

Anyone with a completed document — not just the sender or signers — can confirm it was really completed through Docracy and when, without needing an account. Verify a document.

What Docracy is (and isn't)

Docracy provides simple electronic signatures (SES) with a timestamped audit trail and a certificate of completion. That model is designed to support everyday business documents under US and EU e-signature frameworks — see ESIGN & UETA below.

By default, Docracy does not verify signer identity. Anyone with a signing link can sign as the name on it. The audit trail proves what was signed and when, not who physically signed.

Signed-up accounts (free or paid) can additionally deliver a signer's link over WhatsApp instead of (or alongside) email. That link only reaches a phone number tied to that signer's own WhatsApp account, Meta's delivery/read receipts are recorded in the audit trail next to the existing tamper-evident PDF hash, and a PIN — set by the preparer and required, not optional, on every WhatsApp-delivered link — must be entered before signing, so possession of the phone alone isn't enough. Together, that combination is designed to meet the EU eIDAS criteria for an Advanced Electronic Signature (AES): a signature uniquely linked to and capable of identifying the signatory, created under their sole control, and detectably tied to the signed data. It is not a Qualified Electronic Signature (QES) — we are not a Qualified Trust Service Provider (QTSP), don't issue qualified certificates, and haven't sought third-party AES certification. For contracts that require a QES or a fully identity-verified signature, use a compliance-grade provider.

ESIGN Act & UETA (United States)

Docracy electronic signatures are designed to support the requirements of the U.S. Electronic Signatures in Global and National Commerce Act (ESIGN) and the Uniform Electronic Transactions Act (UETA) for SES-style electronic signatures. We use careful “aligned with / designed to support” language — not a certification or legal guarantee that every document type is enforceable in every jurisdiction.

Under ESIGN and UETA, electronic signatures are generally given legal effect when the parties consent to do business electronically, intend to sign, and an associated record can be retained and accurately reproduced. Docracy’s signing flow is built around those practical requirements:

This is SES-level by default. Paid and Enterprise accounts can additionally turn on WhatsApp-verified signing — the AES-track option described in What Docracy is (and isn't) above — but Docracy still does not provide QES, identity verification, or QTSP services under any plan. Suitability for a given agreement depends on document type, industry rules, and jurisdiction — this page is not legal advice.

EU note: the free-tier SES model is consistent with eIDAS simple electronic signatures for many low-stakes business documents. WhatsApp-verified signing (paid/Enterprise) is designed to meet the higher eIDAS AES bar instead — see above — but we do not claim QES under eIDAS on any plan.

Encryption & transport

Retention & deletion

Anonymous signing chains use a short retention window (default 9 days after creation; configurable up to a product maximum on paid plans). Documents and related signing state are deleted when the TTL expires — or sooner after the chain completes and final copies are emailed. Paid workspaces keep dashboard history and templates according to the account's plan until you delete them or close the account.

Audit trail & completion certificate

For each significant event (view, consent, sign, decline), we record timestamp, IP address, user-agent, and a cryptographic hash of the document content at that point. When a chain completes, parties can download a signed PDF plus a certificate of completion that summarizes that trail.

Infrastructure certifications (Cloudflare)

Docracy runs on Cloudflare (Workers, Pages, KV, R2, D1, and related services). Physical data centers, network edge, and many platform controls are covered by Cloudflare's own compliance program, which includes reports such as SOC 2 Type II and ISO 27001. Customers evaluating Docracy should treat that as shared-responsibility infrastructure evidence — available from Cloudflare under their usual NDA / trust portal process — not as a Docracy-issued SOC 2 or ISO certificate for the application layer.

Docracy (RELACON GmbH) does not hold its own SOC 2 or ISO 27001 attestation. We publish this page and answer questionnaires directly.

Subprocessors

We use the following third parties to operate the service:

ProviderPurposeRegion (typical)
Cloudflare, Inc.Hosting, CDN, compute, storage, bot protection, analyticsGlobal edge; config may pin EU
Resend, Inc.Transactional email (invite, reminder, completion)US / EU depending on Resend routing
Stripe, Inc.Paid plan billing (card payments)US / global Stripe regions
Google LLCOptional Google Drive upload (customer-initiated)Global
Dropbox, Inc.Optional cloud connector (customer-initiated)Global
Microsoft CorporationOptional OneDrive connector (customer-initiated)Global
Box, Inc.Optional Box connector (customer-initiated)Global

Cloud connectors only run when a paid workspace connects them. We do not sell customer data or use advertising trackers.

Access control

Vulnerability testing

We do not publish a recurring third-party penetration-test letter. We welcome responsible disclosure to founder@docracy.io.

Security questionnaire (short answers)

Do you have SOC 2 / ISO 27001?
Not yet for Docracy-as-a-product. Infrastructure is on Cloudflare, which maintains SOC 2 Type II and ISO 27001. Application-layer attestation is roadmap.
Where is data stored?
On Cloudflare's network (Workers/KV/R2/D1). Exact PoP routing is Cloudflare's; contact us if you need a written EU-processing preference for a paid workspace.
Is data encrypted?
Yes in transit (TLS). At rest via Cloudflare platform encryption for R2/KV/D1.
How long do you keep documents?
Anonymous chains: short TTL (default 9 days). Paid history/templates: until deleted or account closed.
Do you support MFA?
Sign-in is passwordless (email magic link). Signing links can use an optional PIN on paid plans. We do not offer TOTP MFA on workspace accounts yet.
Do you process PHI / HIPAA?
No. Docracy is not HIPAA-ready and we do not sign BAAs.
Are signatures ESIGN / UETA compliant?
Docracy SES workflows are designed to support the U.S. ESIGN Act and UETA for many everyday business documents (consent, intent to sign, retainable audit record). We do not verify identity and do not offer AES/QES. See ESIGN Act & UETA above — not a substitute for counsel on high-stakes or regulated agreements.
Do you offer a DPA?
Yes — see Data Processing Agreement for paid / account use. Email sales@docracy.io for a countersigned copy if your legal team requires one.
Breach notification?
We will notify affected account holders without undue delay if we become aware of a personal-data breach affecting their workspace, consistent with GDPR Art. 33/34 obligations where they apply.

Contact

Security or compliance questions: founder@docracy.io · Sales / Enterprise reviews: sales@docracy.io · Legal entity: Imprint