Skip to content

Trust

What we claim, and the proof

This page says where your data lives, who else touches it, and what stands behind each promise on our site. Every claim points at code you can read. Where we cannot prove something, we do not say it.

Where your data lives

Built on SOC 2 Type II audited infrastructure.

The application, the database that holds your account, templates and audit events, and the documents you upload and sign all live in United States regions. The services we use, and what each one receives, are on our sub-processors page.

You can take everything with you at any time: Settings → Export builds one zip of your account with a manifest of checksums, and Settings → Account lets an administrator delete the account, confirmed with their password or a code we email them. Deletion is a 90-day decision: the account goes read-only immediately, and on the date shown it is permanently destroyed, unless you cancel before then.

A few things outlive a permanent deletion, on purpose: the verification record of each signed PDF (its SHA-256 fingerprint, completion date and signer count, kept permanently so a document can still be verified years later; it holds no names and nothing from the document), the subscription and payment history with the person scrubbed out of it, a stub of the account row so those records point at something, and our own log of support access to the account. A file that another account also uses stays for that account. Everything else is destroyed.

The claim register

Every promise our site makes, with the evidence behind it in plain English. The source code is public, so each one can be checked.

Claim register: each marketing claim and the evidence for it
Signer consent is recorded Everyone who signs on our signing pages must first tick "I agree to use electronic records and signatures". That tick is stored as a versioned consent event with the date and time, the signer's IP address, the language the notice was shown in and the SHA-256 fingerprint of the exact disclosure text, and it is printed in the audit trail. The one deliberate exception: a document a sender marks as already completed through the API has no human signer on our pages, so no consent is collected or claimed for it; the audit trail shows it as sender-attested instead.
Signed PDFs are sealed and timestamped Every completed PDF carries a PKCS#7 digital signature made with the EsignCenter platform certificate and an RFC 3161 timestamp from DigiCert's public timestamp authority. If the timestamp service cannot be reached the signing job fails and retries; it never embeds a local clock instead. Change one byte of the file afterwards and the seal no longer checks out.
Anyone can verify a document The verify page needs no account. It checks the file's SHA-256 fingerprint against the record we keep of every PDF we sign, a record that survives account deletion, and confirms our signature on the file. It answers only with the completion date and the number of signers. Names, email addresses and document contents are never shown.
A full audit trail comes with every document A PDF audit trail is generated with each completed document. It lists, in order and with timestamps, when the document was sent, opened, agreed to and signed, by which signer, from which IP address, and includes the verification each signer passed.
Your data is stored in the United States The application, database and files all run in US regions. The providers are listed on the sub-processors page.
You can export everything Settings → Export builds one zip with your templates, documents, signed PDFs, audit trails and CSV records, plus a manifest listing every file with its size and SHA-256 checksum. Anything that could not be included is named in the manifest rather than silently left out.
You can delete your account yourself An administrator can delete the account from Settings → Account, confirmed with their password or an emailed code. The subscription is canceled at once, the account goes read-only, every administrator is emailed the date, and 90 days later everything is destroyed except the records listed under "Where your data lives" above. Any administrator can cancel the deletion before then.
Open source EsignCenter is a fork of DocuSeal. The complete source, including everything on this page, is public under the AGPL at https://github.com/ACED-DevTeam/EsignCenter.
Support access is visible When our support opens a session inside your account, your administrators are emailed at once with the reason, and every session appears in a "Support access" card on your Settings → Account page with who, when, how long, and what changed. Every change the session makes, and every door it is refused at, is logged; the person on our side sees a bright banner the whole time. Support sessions cannot touch billing, passwords, API keys or anything irreversible.
The pricing page tells the truth The comparison table on the pricing page is generated from the same constants the product enforces. The test suite fails if a paid feature is ever gated in the app without appearing in the table.

What we do not claim

EsignCenter itself holds no certifications. The SOC 2 Type II reports behind our infrastructure belong to our hosting and storage providers, not to us: we have no SOC 2 report of our own, no HIPAA assessment, and we do not offer a data processing agreement. If your work needs those, EsignCenter is not the right tool yet, and we would rather say so here than in a sales call.

Nothing on this site is legal advice. Whether an electronically signed document is enforceable depends on the document, the law that applies to it and the people involved; what we can promise is the evidence above, kept accurately, for every document you sign here.

Found a security problem? Tell us on the support form (choose "Security report"), or email support@aceddev.com directly. A real person reads it.

Check a document

Upload any PDF and learn whether it was completed through EsignCenter, when, and by how many signers.

Verify a document