What DocuSign publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.
"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.
Says it does not train AI on customer data
DocuSign's own words (docusign.com/privacy):
Google Workspace APIs and Customer Data obtained through such APIs are not used to develop, improve, or train generalized AI and/or ML models.
| Certification or report | Mentioned on |
|---|---|
| SOC 2 Type II | docusign.com/trust/compliance |
| SOC 1 | docusign.com/trust/compliance |
| ISO/IEC 27001 | docusign.com |
| HIPAA | docusign.com/trust/compliance |
| PCI DSS | docusign.com |
| FedRAMP | docusign.com |
| CSA STAR | docusign.com |
Privacy laws and frameworks mentioned: CCPA/CPRA. These are laws the vendor says it follows, not certifications.
A certification on a website is a claim. For anything sensitive, ask DocuSign for the SOC 2 report or ISO certificate.
DocuSign publishes its subprocessor list at docusign.com/trust/alerts/update-subprocessor-list-for-docusign-services-october-8-2026, but it couldn't be read automatically. Open it directly.
| SSO / SAML | Not found |
| SCIM provisioning | Not found |
| Multi-factor authentication | Not found |
| Encryption at rest | Not found |
| Encryption in transit | Not found |
| Penetration testing | Not found |
| Bug bounty / disclosure program | Not found |
| Audit logs | Not found |
| Data residency | Not found |
| security.txt contact | Not found |
| Trust / security center | docusign.com/trust |
| Privacy policy | docusign.com/privacy |
| Subprocessor list | docusign.com/trust/alerts/update-subprocessor-list-for-docusign-services-october-8-2026 |
| Data processing agreement (DPA) | Not found |
| AI policy | Not found |
| Terms | Not found |
| Status page | health.docusign.com/status |
| Check | Points | Result |
|---|---|---|
| Security or trust page | 15 | Yes |
| Certifications listed | 20 | Yes |
| Privacy policy | 10 | Yes |
| Subprocessor list | 15 | Yes |
| DPA available | 10 | No |
| AI training policy stated | 15 | Yes |
| security.txt contact | 5 | No |
| Status page | 10 | Yes |
The score measures how much of a standard security review our reader could answer from DocuSign's public pages. It is not a rating of how secure DocuSign is, and a "No" can mean the document exists where our reader couldn't see it.
Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.
Airtable · Asana · Atlassian · Basecamp · Box · Calendly · ClickUp · Coda · Dropbox · Evernote · Figma · Fireflies.ai
Source: DocuSign's own public website (5 pages read on October 10, 2026). Stormap is not affiliated with DocuSign. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.