Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with DocuSign, your compliance team needs documented proof they can be trusted. ThirdProof investigated DocuSign across 27 intelligence sources — here's what we found.
✓ FedRAMP Status: Authorized (Moderate) — verified against marketplace.fedramp.gov
24 sources queried. 98% confidence. Every DocuSign investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get DocuSign's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 32% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
DocuSign is ISO 27001:2022, ISO 27017:2015 and 27018:2019 certified.
Q41
FedRAMP authorized: Product: DocuSign CLM; Provider: DocuSign; Status: Compliant; Impact Level: Moderate; Authorization Date: 2022-09-27T04:00:00.000Z
Q40
DocuSign signs Business Associate Agreements (BAA) with customers required by law to comply with HIPAA as a certified BAA provider.
Q42
DocuSign provides Data Protection Attachment and DPA documentation governing processing of Personal Data by DocuSign as a Processor on behalf of customers.
+ 3 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get DocuSign's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Verified against the official FedRAMP Marketplace API as of March 2026.
DocuSign authorized at Moderate impact level.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
24
Sources Queried
23
Sources With Data
March 25, 2026
Last Assessed
AI-generated analysis for Docusign
DocuSign (docusign.com) is a publicly traded, enterprise-grade electronic signature and agreement management platform with a long-established market presence, assessed at Tier 3 (Moderate Risk) with 98% confidence across 24 independent data sources. The investigation identified several strong positive signals supporting DocuSign's overall credibility and security posture:
Independence Statement
All evidence in this report was independently sourced from external data providers and public registries without vendor participation, notification, or input.
6 findings identified for Docusign
Article from Yahoo! News: "5 Must-Read Analyst Questions From DocuSign’s Q4 Earnings Call"
docusign.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.
docusign.com received a mediocre grade (C). Some security headers are configured but improvements are needed.
docusign.com has certificates from 40 different Certificate Authorities. This may indicate inconsistent certificate management practices.
No accessible subprocessor page was found for docusign.com. GDPR Article 28 requires data processors to maintain a list of subprocessors. Vendors with mature data governance typically publish this list.
1 article(s) mention "DocuSign" with risk keywords, severity reduced due to article age: "Breach at DocuSign Led to Targeted Email Malware Campaign" (Krebs on Security) https://news.google.com/rss/articles/CBMimgFBVV95cUxOcTFqeHdtSHhibmthUHJ1cTlwTmxlNGlpTlJNelBGMlFMQ0pHMlBWZk1BZDI3NFRrSEF0QVFDak1rUVJzQjAxYzNoWkJzNXJmT1F3RlJYT0JiQUNzYjBsdlNuMUtQamJ5eE9ZWDZZbE5mS3JGM2JJMERqbUlKaDUzT0FfQ19MUVFWZFBjS01GTkRLb2N6YzM0bnh3?oc=5
19 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (26+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: trust
Tech Community Sentiment →Large Certificate Footprint (641 subdomains)
Certificate Transparency →Established Web Presence (25+ years)
Web Archive History →Domain in 50 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for Docusign
Request DocuSign's current SOC 2 Type II report and a bridge letter covering the period since the last audit — contact their security team or check their community trust page at https://community.docusign.com/esignature-111/soc-2-report-2981. Many enterprise accounts can access this through their account representative.
Request DocuSign's current subprocessor list and Data Processing Agreement (DPA) directly from their legal or privacy team. For GDPR-scoped deployments, ensure the DPA includes subprocessor change notification clauses with adequate notice periods.
Confirm ISO 27001 certification status directly with DocuSign's security team, as the public registry was unreachable during this investigation. Ask for the certificate number, issuing body, and validity dates.
Clarify DocuSign's AI data handling practices by asking their team specifically: (a) whether customer agreement data is used to train AI models, (b) the retention period for data processed by AI features, and (c) which third-party AI providers (if any) process your organization's data. Request written confirmation or updated DPA addendum if AI features are in scope.
Configure organization-wide email security controls to detect and flag DocuSign-themed phishing — this is independently confirmed as a top inbox threat category. Provide user awareness training referencing the 'Broken Seal' and similar DocuSign-impersonation campaign patterns.
24 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you DocuSign? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is DocuSign on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is DocuSign's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is DocuSign a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has DocuSign appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is DocuSign's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are DocuSign's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does DocuSign claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does DocuSign depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has DocuSign appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate DocuSign and every other vendor in your stack — average report time: 7 minutes. Get DocuSign's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates DocuSign across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.