VendorScore · E-signature · Data-access posture

Can Docusign read your contracts?

A plain-language answer from Docusign's Trust Center, Security Appliance page, subprocessor list, Data Protection Attachment and AI blog. Docusign's claim that staff can't view agreements is its own statement, not end-to-end encryption.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, by design (with controls): Docusign's cloud and AI features process your agreements; it says key management keeps staff from content, but that's a vendor claim, not E2EE.

67 / 100 overall

Scored configuration: Docusign eSignature/IAM enterprise with Security Appliance (envelope keys in an appliance or HSM behind your firewall), EU data region, AI data-use toggle off, envelope purge policies.

Default setup (Docusign-managed keys) scores lower; the report estimates Overall ~60.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Docusign's public documentation:

  • Docusign's AI data-controls support article is JavaScript-only; we confirmed it via a search index only.
  • Docusign's absolute 'personnel cannot view' statement isn't E2EE and isn't reconciled with AI processing of agreement content.
  • Whether AI features work on Security Appliance-encrypted envelopes is not documented.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Docusign data access, AI training, GDPR and residency

Can Docusign read your contracts?

Yes, by design (with controls): Docusign's cloud and AI features process your agreements; it says key management keeps staff from content, but that's a vendor claim, not E2EE. VendorScore rates Docusign 67/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Docusign eSignature/IAM enterprise with Security Appliance (envelope keys in an appliance or HSM behind your firewall), EU data region, AI data-use toggle off, envelope purge policies.

Is Docusign end-to-end encrypted? What does Security Appliance do?

No. Docusign encrypts agreements at rest with AES-256 and in transit with TLS 1.2, which is server-side encryption, and makes no end-to-end encryption claim. Security Appliance, a premium eSignature add-on, lets you control envelope encryption keys in an appliance or HSM behind your firewall; without it, Docusign manages the keys. Whether AI features work on Security Appliance-encrypted envelopes isn't documented.

Can Docusign employees read my contracts?

Docusign says they can't, but that's its claim, not E2EE. Docusign states that "Docusign personnel cannot view or access the contents of your Agreement Data" and credits its encryption and key management. VendorScore treats this as a vendor claim: the service still renders documents for signers and sends content to AI providers for AI features. Staff get limited access to transactional metadata with manager, owner and security approvals, and Docusign says it can't delete or export transaction data (which excludes document contents), even on request.

Does Docusign train AI on my agreements?

It depends on your contract. Docusign says: "we only use data that is anonymized and aggregated, from customers who have given consent via their contract, including those who purchase an IAM plan on Docusign's website." With contractual consent the in-product setting starts on and admins can turn it off; without consent the toggle is disabled and off. Self-serve IAM web purchases count as consent, so the toggle starts on for them. Docusign's AI data-controls support article is JavaScript-only, and we confirmed it via a search index only.

Is Docusign GDPR compliant? Where is the Docusign DPA?

VendorScore doesn't certify compliance; Docusign publishes a DPA at https://www.docusign.com/legal/terms-and-conditions/data-protection-attachment. Docusign's Data Protection Attachment gives 30 days' prior notice of a new subprocessor, with a termination right if an objection can't be resolved, and relies on SCC Modules 2/3 and Binding Corporate Rules.

Who are Docusign's subprocessors? Which AI providers see my agreements?

Docusign's list (updated 2026-09-18) at https://www.docusign.com/trust/privacy/subprocessors-list names Docusign group members with "follow the sun" support; infrastructure from 365 Data Centers, Centersquare, Equinix and Microsoft Azure; AI providers Microsoft Azure OpenAI, Azure Document Intelligence and Google Vertex AI Gemini, including global endpoints; and many identity-verification and support providers. Docusign doesn't publish zero-data-retention terms with the AI providers.

Can I keep Docusign data in the EU?

Yes. Docusign offers five data regions: US, Canada, Europe, Australia and Japan. Its AI subprocessors include global endpoints.

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (docusign.md), evidence dated 2026-10-07.