Skip to content
ZiaSignZiaSign
ZiaSign
  • Solutions
  • Free PDF Tools
  • Docs
  • Pricing
  • Company

    • About
    • Blog
    • Investors
    • Acquire (M&A)
    • Security

    Compare

    • vs DocuSign
    • vs Adobe Sign
    • vs PandaDoc
    • vs iLovePDF
    • vs Smallpdf
    • vs PDF24
    • vs Sejda
    Investor connectLatest blog
PDF ToolsFreePricing
Start Free
Start Free

Platform

  • AI Document Intelligence
  • eSignature & Signing
  • Templates & Workflows
  • Pricing
  • What's New

Solutions

  • Individuals & Teams
  • Developers & API
  • Enterprise
  • Trust & Security

Free PDF Tools

  • Browse All Tools
  • Merge PDF
  • Split PDF
  • Compress PDF
  • PDF to Word
  • Use-Case Guides

Developers

  • Documentation
  • API Reference
  • How-To Guides
  • Status

Compare

  • vs DocuSign
  • vs Adobe Sign
  • vs PandaDoc
  • vs iLovePDF
  • vs Smallpdf
  • vs Sejda

Company

  • Invest in ZiaSign
  • Acquire ZiaSign
  • Blog
  • Privacy
  • Privacy Choices
  • Terms
  • DPA
ZiaSignZiaSign
ZiaSign

Trusted documents. Faster.

© 2026 ZiaSign. All rights reserved.

SOC 2 (in audit)GDPR · DPDPeIDAS · ESIGN
Trust Center

Verifiable security. Honest about audit.

One page for procurement, security and legal teams. Standards link to their source. Audit status is current, not aspirational. The DPA, sub-processor list and AI policy are public.

See the receiptsRead the DPA
0AI training on customer data
3Residency regions
99.99%Target API SLA
24hCritical patch target
System statusCompliance & attestationsSecurity controlsAI safetyData processingSub-processorsResponsible disclosureContact

01 · Availability targets

Built to stay up

Availability targets for each platform component. For current status or incident history, contact [email protected] — a public status page is on the roadmap.

  • API (api.ziasign.com)
    Target 99.99%
  • Web app (ziasign.com)
    Target 99.95%
  • Signing service
    Target 99.99%
  • AI inference
    Target 99.9%
  • Webhook delivery
    Target 99.95%
  • Email delivery
    Target 99.9%

Subscribe to incident notifications: [email protected]

02 · Compliance & attestations

Standards, not stickers.

Each entry below states what is active, what is in progress, and which standard it maps to. We do not display certifications we do not hold.

SOC 2

Type II

Audit in preparation

Type I controls implemented and operating. Type II audit preparation is underway with an external CPA firm. Current status and evidence available under NDA upon request.

ISO 27001

Controls

Implemented · cert pending

Annex A control set implemented and mapped against our ISMS. External certification audit scheduled following SOC 2 Type II closure.

GDPR

Compliant

Active

Article 28 Data Processing Agreement available below. Standard Contractual Clauses (SCCs 2021/914) included for international transfers. EU data residency available.

DPDP Act

India

Active

Designed for the Digital Personal Data Protection Act 2023. Indian data residency, consent-management primitives, and Significant Data Fiduciary obligations supported.

eIDAS

Advanced

EU 910/2014 aligned

Advanced Electronic Signature (AdES) implementation aligned to Regulation (EU) 910/2014. Qualified signatures (QES) are on the roadmap via accredited Qualified Trust Service Providers and are not offered today.

ESIGN · UETA

US

Active

Compliant with the Electronic Signatures in Global and National Commerce Act (ESIGN, 15 U.S.C. § 7001) and the Uniform Electronic Transactions Act (UETA) as adopted by 49 US states.

HIPAA

Aligned

BAA available

Administrative, physical and technical safeguards aligned to 45 CFR §§ 164.308–312. Business Associate Agreement available on enterprise plans.

Audit trail

Hash chain

Active

Every envelope action is recorded in a tamper-evident, hash-chained audit trail. Each event hash covers all material fields and links to the previous event, so removal or alteration is detectable on verification.

03 · Security controls

Defense in depth, by default.

Encryption at rest

AES-256-GCM via cloud-provider KMS. Per-tenant data keys with envelope encryption.

Encryption in transit

TLS 1.3 only on all public endpoints. HSTS preload, perfect forward secrecy, modern cipher suites.

Key management

BYOK / customer-managed keys (CMK) on enterprise plans. Annual key rotation, audited.

Access control

SSO via SAML 2.0 / OIDC, SCIM provisioning, granular RBAC, IP allow-listing, step-up MFA on signing events.

Audit logging

Tamper-evident, append-only audit log of every access and signing event. Exportable in CEF, JSON and CSV.

Data residency

Tenant-pinned residency in US (us-east-1), EU (eu-central-1) and India (ap-south-1). No cross-region replication without consent.

Penetration testing

Annual third-party penetration test by an independent CREST-accredited firm. Executive summary available under NDA.

Vulnerability program

Continuous SCA + SAST + DAST. Dependency patching SLA: critical < 24h, high < 7d. Responsible disclosure at [email protected].

04 · AI safety & data handling

Your contracts will not train anyone's model.

AI is the third rail of enterprise procurement in 2026. Here is exactly what we do and do not do — contractually guaranteed in our DPA.

01

We do not train on your data

Customer documents, signatures, audit logs and metadata are never used to train foundation models — ours, our vendors', or anyone else's. This is contractually guaranteed in our DPA and enforced via zero-retention API agreements with our model providers.

02

Inference is region-pinned

AI inference for an envelope runs in the customer's tenant region. EU tenants do not see their data routed to US inference endpoints. Region routing is enforced at the edge.

03

No persistent context

AI context windows are scoped to a single request and discarded immediately. We do not maintain persistent embeddings of customer contracts unless the customer explicitly enables semantic search (and even then, embeddings live in the tenant's region only).

04

Frozen, version-pinned models

We pin to specific model snapshots (e.g. gpt-4.1-2025-04, claude-sonnet-4-5-20250929). Upgrades require change management and customer notification on enterprise plans.

05

Human-in-the-loop for material changes

AI cannot finalize, send for signature, or execute a contract without explicit human approval. AI is an assistant, not an actor.

Model provider contracts: we operate on the zero-retention API tier with OpenAI and Anthropic, and have signed enterprise DPAs with both. Customer prompts and completions are not retained beyond the request lifecycle and are not eligible for model training.

05 · Data processing

DPA, SCCs and customer rights.

Data Processing Agreement

Our DPA is GDPR Article 28 compliant and incorporates the European Commission's 2021 Standard Contractual Clauses for international transfers. It governs the processing of personal data when you use ZiaSign as a Processor.

  • GDPR Art. 28 compliant
  • SCCs 2021/914 included
  • UK IDTA addendum on request
  • DPDP Act (India) provisions
  • CCPA/CPRA service-provider terms
  • Sub-processor flow-down
Read full DPA Request counter-signed copy

06 · Sub-processors

Who touches your data.

We disclose every sub-processor that may process customer personal data. Customers can subscribe to change-notifications and have a 30-day objection window before any new sub-processor goes live.

ProcessorPurposeRegions
Amazon Web Services (AWS)Primary cloud infrastructureus-east-1, eu-central-1, ap-south-1
Microsoft AzureSecondary infrastructure, AKS for control-plane servicesEU North, India South
OpenAIAI inference (clause extraction, summarization)Customer-region routing, no training opt-in
AnthropicAI inference (review-side reasoning)US, EU; zero-retention API tier
ResendTransactional email deliveryEU
CloudflareEdge CDN, WAF, DDoS protectionGlobal
Full sub-processor list Subscribe to change-notifications

07 · Responsible disclosure

Find a vulnerability? Tell us first.

Acknowledge

< 24h

Initial response from a security engineer

Triage

< 72h

Severity assigned, repro confirmed, ticket opened

Patch SLA

Critical < 24h

High < 7d · Medium < 30d · Low next release

Report security issues to [email protected]. PGP key available on request. We commit to non-retaliation against good-faith researchers and will credit reporters in our hall of fame on request.

08 · Contact

Get in touch.

[email protected]

Security & vulnerability disclosure

[email protected]

Privacy, GDPR & DPDP requests

[email protected]

Counter-signed DPA, MSA, BAA

[email protected]

Vendor security questionnaires

Last reviewed: 23 April 2026 · Page is updated within 5 business days of any material change.