Trust & Security

Your contract never leaves your control. Not even to get signed.

Most signing platforms upload your document to a third party to have a signature applied. We don't — where a licensed provider must sign, we send a cryptographic hash and nothing else. Every safeguard on this page is something your security team can verify directly, not just take our word for.

AES-256Encryption at rest and in transit
256-bitAES encryption at rest
99.9%Platform uptime

Not just secure. Provably secure.

"Trust us" isn't good enough for your security team, and we don't expect it to be — every control below is independently audited and open to their own review.

  • Hardened, access-controlled infrastructure, GDPR & CCPA aligned
  • SSO / SAML and granular role-based permissions
  • Immutable audit trail on every edit, comment and signature
  • Every clause cites the counsel-reviewed library it came from — drafts are auditable, not improvised
  • Every signer identity-verified through Docsliy Verify — government ID checks, biometric liveness and KYC screening
AES-256 Encrypted GDPR CCPA SSO / SAML Identity Verified

The document never transits a third party

In many jurisdictions the signature must be applied by a licensed provider. Most platforms satisfy that by uploading your contract to them. We satisfy it with a hash.

  • Only a SHA-256 hash is sent to the signing authority — never the file
  • The hash binds the signature to that exact document and exposes any later edit
  • Identity verification sees the signer's ID — not the agreement they're signing
  • Indian customer data is stored in-region; Enterprise plans can pin residency contractually
  • Instruments the local law excludes are refused rather than silently executed
Hash-only signing Data residency 99.9% uptime
Not Every Signature Holds Up

Sign with the wrong tier, and the agreement may not hold up. Docsliy gets it right by default.

Every jurisdiction sets its own bar for what counts as a legally binding signature — get the tier wrong and enforceability is the first casualty. Docsliy supports SES, AES and QES natively, so the right one is always applied.

SES

Simple Electronic Signature

For everyday agreements — NDAs, internal approvals, low-risk vendor terms.

  • Click-to-sign in seconds
  • Full audit trail on every signature
  • Legally recognized in most jurisdictions
AES

Advanced Electronic Signature

For business-critical contracts that need stronger identity assurance.

  • Verified signer identity
  • Tamper-evident sealing
  • Uniquely linked to each signer
QES

Qualified Electronic Signature

For regulated industries where the law demands the highest bar.

  • Qualified certificate from a trusted provider
  • eIDAS equivalence to a handwritten signature
  • Highest evidentiary weight in court

Custom Field Support

Initials, dates, checkboxes and conditional fields, placed exactly where you need them.

Progress Tracking & Reminders

See who's signed, who's pending, and nudge automatically without lifting a finger.

API-First Signing

Trigger, track and embed signing flows directly from your own product or CRM.

Multi-Party Workflows

Sequential or parallel signing across as many parties as the deal requires.

A signature that's valid in one country can be worthless in another

SES, AES and QES carry different legal weight depending on where your signer is — get it wrong and enforceability is the first thing to go. Our Legality Guide breaks it down market by market — the United States, the European Union, the United Kingdom, India and Australia.

Open the eSignature Legality Guide
FAQ

Still have doubts? Here's every answer.

Encryption, audit, data residency, and who can see what.

From clause libraries reviewed by counsel qualified in the relevant jurisdiction, plus your own approved playbook — not from a model writing law from memory. Every clause cites the library it came from, so a draft can be audited back to its source. It remains a drafting aid, not legal advice, and should be reviewed before it's relied on.
A SHA-256 hash of the document, plus the signer reference needed to issue the certificate. Not the contract, not its contents, not its metadata. The hash is a one-way fingerprint — it proves the signature belongs to that exact file and reveals any later alteration, but it cannot be reversed to reconstruct the document.
All data is encrypted in transit and at rest with 256-bit encryption, access is governed by role-based permissions, and every access event is written to an immutable audit log.
Data is encrypted at rest with AES-256 and in transit with TLS 1.3, on hardened, access-controlled infrastructure. Indian customer data is stored in-region. Enterprise plans can pin data residency contractually — useful where a regulator or your own policy requires it.
Nothing is charged automatically. When your 14 days are up, you choose the plan that fits — your drafts and data stay exactly where you left them.
Yes. Legal defines the approved clause library and risk thresholds once; every draft generated by sales, HR or finance automatically stays inside those guardrails.
Have a Security Questionnaire?

Stuck waiting on security sign-off? Let's get it moving.

Talk to our team about our security controls, DPAs, and anything else procurement needs before you sign on.