VendorScore · E-signature · Data-access posture
A plain-language answer from Docusign's Trust Center, Security Appliance page, subprocessor list, Data Protection Attachment and AI blog. Docusign's claim that staff can't view agreements is its own statement, not end-to-end encryption.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, by design (with controls): Docusign's cloud and AI features process your agreements; it says key management keeps staff from content, but that's a vendor claim, not E2EE.
Scored configuration: Docusign eSignature/IAM enterprise with Security Appliance (envelope keys in an appliance or HSM behind your firewall), EU data region, AI data-use toggle off, envelope purge policies.
Default setup (Docusign-managed keys) scores lower; the report estimates Overall ~60.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Security Appliance lets customers control envelope encryption keys behind their own firewall (premium add-on).
Evidence: Docusign Security ApplianceDocusign states its personnel cannot view or access Agreement Data contents; that's Docusign's claim about its server-side key management, not E2EE. Staff get limited, approved access to transactional metadata.
Evidence: Docusign data management & privacyAI features use Azure OpenAI and Google Vertex AI Gemini, including global endpoints.
Evidence: Docusign subprocessor listOur report flags these gaps in Docusign's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, by design (with controls): Docusign's cloud and AI features process your agreements; it says key management keeps staff from content, but that's a vendor claim, not E2EE. VendorScore rates Docusign 67/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Docusign eSignature/IAM enterprise with Security Appliance (envelope keys in an appliance or HSM behind your firewall), EU data region, AI data-use toggle off, envelope purge policies.
No. Docusign encrypts agreements at rest with AES-256 and in transit with TLS 1.2, which is server-side encryption, and makes no end-to-end encryption claim. Security Appliance, a premium eSignature add-on, lets you control envelope encryption keys in an appliance or HSM behind your firewall; without it, Docusign manages the keys. Whether AI features work on Security Appliance-encrypted envelopes isn't documented.
Docusign says they can't, but that's its claim, not E2EE. Docusign states that "Docusign personnel cannot view or access the contents of your Agreement Data" and credits its encryption and key management. VendorScore treats this as a vendor claim: the service still renders documents for signers and sends content to AI providers for AI features. Staff get limited access to transactional metadata with manager, owner and security approvals, and Docusign says it can't delete or export transaction data (which excludes document contents), even on request.
It depends on your contract. Docusign says: "we only use data that is anonymized and aggregated, from customers who have given consent via their contract, including those who purchase an IAM plan on Docusign's website." With contractual consent the in-product setting starts on and admins can turn it off; without consent the toggle is disabled and off. Self-serve IAM web purchases count as consent, so the toggle starts on for them. Docusign's AI data-controls support article is JavaScript-only, and we confirmed it via a search index only.
VendorScore doesn't certify compliance; Docusign publishes a DPA at https://www.docusign.com/legal/terms-and-conditions/data-protection-attachment. Docusign's Data Protection Attachment gives 30 days' prior notice of a new subprocessor, with a termination right if an objection can't be resolved, and relies on SCC Modules 2/3 and Binding Corporate Rules.
Docusign's list (updated 2026-09-18) at https://www.docusign.com/trust/privacy/subprocessors-list names Docusign group members with "follow the sun" support; infrastructure from 365 Data Centers, Centersquare, Equinix and Microsoft Azure; AI providers Microsoft Azure OpenAI, Azure Document Intelligence and Google Vertex AI Gemini, including global endpoints; and many identity-verification and support providers. Docusign doesn't publish zero-data-retention terms with the AI providers.
Yes. Docusign offers five data regions: US, Canada, Europe, Australia and Japan. Its AI subprocessors include global endpoints.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (docusign.md), evidence dated 2026-10-07.