Security at zSign
Last updated: September 8, 2026
Overview
This page states the security and hosting facts zSign can currently document. It is a description of how the product is built today, not a certification badge page and not legal advice.
Encryption
Data is encrypted in transit with TLS. Signing links use signed, per-recipient tokens; stored tokens are hashed.
Documents are encrypted at rest using standard server-side encryption from our cloud storage provider (AES-256, provider-managed keys). zSign does not currently offer customer-managed encryption keys (CMEK) or customer-supplied keys (CSEK).
Audit trail and sealed documents
Completed envelopes include an audit trail (IP address, view and signature timestamps, consent, and a SHA-256 hash of the document) and a tamper-evident sealed PDF with a completion certificate.
Teams sometimes call that artifact court-ready evidence — that phrase is descriptive of the artifact, not a promise that a court will enforce any particular document. See agent-sent envelopes for the same disclaimer in full.
Not legal advice. zSign is not a law firm and does not provide legal advice. We do not guarantee that any signature or document will be enforceable in every jurisdiction or for every document type. The sender is responsible for determining whether electronic signature is appropriate. See Terms and Privacy.
Hosting
Primary infrastructure is hosted in the United States. We do not currently offer a customer-selectable data region.
Subprocessors
We use processors for hosting, database, document storage, email, payments, support, and analytics. Contact support@zsign.io for the current list. See also the Privacy Policy.
What we don’t claim
This page does not claim SOC 2, ISO, HIPAA, or FedRAMP certification. zSign does not currently offer customer-managed encryption keys (CMEK), customer-supplied keys (CSEK), or a customer-selectable data region.
Report a vulnerability
Report suspected vulnerabilities to support@zsign.io.