Legal compliance and security

Legally binding, provably intact.

Legally valid in 50+ countries and 60+ jurisdictions. Every executed document leaves with the evidence file on the right: a PKI-signed certificate, a tamper-evident seal, and the full event history your counsel can hand to a court.

SOC 2 Type IHIPAA compliantESIGN & UETAeIDAS SES / AESGDPR
Certificate of completion
envelope 8f42-a913 · policy endorsement
● Tamper-evident
Event history
Envelope sent
via API
09:41:03 UTC
Document viewed
Signer 1
09:44:17 UTC
Identity verified
KBA passed
09:44:52 UTC
Document signed
Signer 1
09:47:30 UTC
Completed and sealed
PKI certificate issued
09:47:31 UTC
sha256 4c9f…e21a · signed 2048-bit RSAPKI verified
AICPA SOC 2 sealIndependently attestedAICPA SOC 2 Type Ireport available on request
ESIGN ActUS federal law15 U.S.C. § 7001
UETAUS state lawUniform Act, 1999
eIDASSES and AES · QES via TSPsRegulation (EU) 910/2014
HIPAAcontrols aligned to the Security Rule45 C.F.R. Part 164
GDPRdata processing addendum, applied automaticallyRegulation (EU) 2016/679
50+
countries where signatures are legally valid
60+
jurisdictions covered
2048
bit RSA keys, held in HSMs
8
recipient authentication levels

Enterprise-grade security for your most sensitive agreements

Legally binding

Every signature is ESIGN Act and UETA compliant, with eIDAS SES and AES support and QES available through qualified trust service provider partnerships.

Tamper-evident documents

Digital signatures and a tamper-evident seal mean nobody ever questions document integrity.

PKI digital signatures

Public Key Infrastructure, the standard trusted by banks and governments, backs every executed document with public and private certificates.

Audit trail and certificate

A digital log and signed certificate record when and where a document was signed, and by whom.

Encryption in HSMs

Documents are encrypted with 2048-bit RSA private keys stored in secure Hardware Security Modules: no unauthorized access, including by Verdocs developers.

SOC 2 Type I, attested

Independent attestation of our information security posture. The report is available on request under a mutual NDA.

HIPAA compliant

Workflows carrying health information run under HIPAA-aligned controls.

Enterprise-grade infrastructure

Data centers run on AWS and Azure.

For EU workflows

The three eIDAS tiers, plainly

SESSupported today
Simple Electronic Signatures

The standard tier for most business agreements across the EU.

AESSupported today
Advanced Electronic Signatures

Uniquely linked to the signer with tamper-evident integrity.

QESVia qualified TSP partnerships
Qualified Electronic Signatures

The highest eIDAS tier, available where a customer use case requires it.

Where Verdocs signatures are legally valid

Legally valid in 50+ countries and 60+ jurisdictions, per the canonical list in our developer FAQ.

Americas
United StatesCanadaBrazilMexico
Europe
United KingdomAll 27 EU member states
Asia-Pacific
AustraliaNew ZealandSingaporeJapanSouth KoreaIndia
Africa
South Africa

Identity assurance that scales with the stakes

Layer recipient authentication per document, from a shared link to a live ID scan.

Creator linkIn-person linkGuest emailPIN codeVerified userMFA / SMSKBAID scan

Common questions

Are Verdocs signatures legally binding?

Yes. Signatures are ESIGN Act and UETA compliant and legally valid in 50+ countries and 60+ jurisdictions, including all EU member states under eIDAS (SES and AES, with QES through qualified trust service provider partnerships).

Will a Verdocs document hold up if challenged?

Every executed document carries a PKI digital signature, a tamper-evident seal, a digitally signed certificate, and a full audit trail recording when, where, and by whom it was signed.

Can we review the SOC 2 report?

Yes. The SOC 2 Type I report is available on request under a mutual NDA. Fill in the request form on this page and the NDA is generated straight away; the report follows once it is signed by both sides.

How is signer identity verified?

Authentication layers to the risk of the document: creator and in-person links, guest email, PIN codes, verified accounts, MFA and SMS, knowledge-based authentication, and live ID scans.

More questions? The full FAQ lives in the developer docs, from API auth and webhooks to eIDAS signature levels.

Your security team wants the details. Good.

The SOC 2 Type I report goes out under a mutual NDA. Tell us who is asking and we generate the NDA straight away, so you are not waiting on a sales call to get a document your review needs.

Diligence questionnaires go to support@verdocs.com. If you would rather talk it through first, a meeting works too.

These details populate a mutual NDA. You sign it, we countersign it, and the report follows.

Or email us instead