Built for operators who can't afford a signature that doesn't hold up.
OtterSign is independently audited and built to protect the waivers, agreements, and data your business depends on. Here’s an inside look at how we secure your account, your signers, and every document in between.
SOC 2
Type I & Type II
HIPAA
Aligned practices
GDPR · CCPA
CA, NY & CO ready
24/7
Monitoring & support
Independently audited, not just self-declared.
OtterSign has completed both stages of the SOC 2 audit, verified by an independent third-party auditor.
- Completed
SOC 2 Type I
Confirms that OtterSign's security controls were suitably designed at a specific point in time — covering access control, encryption, change management, and monitoring across the platform.
Auditor: Thoropass
- Completed
SOC 2 Type II
Confirms those same controls operated effectively over an extended observation period — the deeper, ongoing-proof standard enterprise buyers and compliance teams ask for.
Auditor: Thoropass
Waivers and agreements that hold up where it counts.
OtterSign is built around the laws that govern electronic signatures, the privacy rules that govern the data behind them, and the vendor and payment boundaries that keep everything else contained — nationally and in the states with the strictest requirements.
ESIGN Act & UETA
The federal ESIGN Act and state-level UETA require four things for a signature to be legally binding: intent to sign, consent to do business electronically, a clear association between the signature and the record, and retention of that record. Every OtterSign signature carries a timestamped audit trail that documents each of these — who signed, what they agreed to, and when.
GDPR
For EU signers and subscribers, OtterSign processes personal data on a lawful basis, collects only what’s needed to deliver the service, and honors requests to access, correct, or delete personal data. Data handling terms for customers processing EU data are set out in our Data Processing Agreement, available on request.
California (CCPA/CPRA)
California residents have the right to know what personal information OtterSign collects, request its deletion, and opt out of its sale or sharing. OtterSign does not sell personal information, and CCPA/CPRA rights requests are honored without requiring account changes that would discriminate against the requester.
New York (SHIELD Act)
New York’s SHIELD Act requires reasonable administrative, technical, and physical safeguards for private information, plus timely breach notification. OtterSign’s encryption, access controls, and incident response process are built around those same requirements.
Colorado Privacy Act
Colorado residents can access, correct, delete, and obtain a copy of their personal data, and opt out of targeted advertising and profiling. OtterSign limits data collection to what’s needed for the service consistent with the Act’s purpose-limitation requirement.
HIPAA-Aligned Practices
OtterSign follows safeguards modeled on the HIPAA Security Rule’s administrative, physical, and technical categories — encryption, access logging, and workforce training among them. OtterSign is not a HIPAA-certified platform; operators handling protected health information should confirm fit for their specific use case before relying on it as their sole safeguard.
Payments & PCI Scope
OtterSign doesn’t process or store cardholder data directly. Payment collection — including the Digital Access Card flow connecting OtterSign to OtterOrder — hands off to OtterOrder’s checkout, keeping card data out of OtterSign’s systems entirely.
Third-Party Subprocessors
Vendors that touch customer or signer data — cloud hosting, email delivery, SMS carriers — are reviewed before onboarding and periodically after, and are bound by agreements requiring them to meet OtterSign’s data-handling standards. A current subprocessor list is available on request.
The controls behind the audit.
SOC 2 is the proof; here’s what it’s actually verifying about how we run the platform day to day.
01
Encryption in transit & at rest
Customer and subscriber data is encrypted using TLS in transit and encrypted at rest across our infrastructure.
02
Role-based access control
Internal access to production systems and customer data is scoped by role, logged, and reviewed on a recurring basis.
03
Cloud infrastructure on AWS
Core signing, storage, and messaging infrastructure runs on Amazon Web Services with its own independently audited controls.
04
Continuous monitoring
Systems are monitored around the clock, with alerting tied into an internal incident response process.
05
Vendor & subprocessor review
Third-party vendors that touch customer or signer data are reviewed before onboarding and periodically thereafter.
06
Employee security training
Team members complete security and confidentiality training as part of onboarding and on an ongoing basis.
Every signature leaves a defensible trail.
When a document goes out for signature, OtterSign generates a unique record ID for that signing session and attaches a signature certificate to the document itself. That ID can be used to look up exactly who signed, when, and what happened leading up to it — giving you documented proof of access, review, and signature if an agreement is ever challenged.
This applies across every way a document reaches a signer — a shared link, a QR code, a kiosk, or an ID-verified signing flow — and it’s on by default. Nothing extra to configure.
Audit-tracked events include
Document sent
Document viewed
Electronic Record & Signature Disclosure accepted
Signer details captured
ID verification completed (4D Scanning)
Kiosk / QR signing activated
Document signed
Decline to sign, with reason if provided
SMS & marketing consent captured
Not exhaustive — newer signing paths add their own tracked events as they ship.
Compliance your signers can feel, too.
Trust isn’t just an audit report — it’s what happens every time someone signs a waiver, checks in at a kiosk, or asks what happens to their information.
- Signature integrity
Every signature is backed by the tamper-evident audit trail detailed above — timestamp, record ID, and signer identity, so it can be verified later if it’s ever challenged.
- SMS opt-in & STOP/HELP handling
SMS automation runs on OtterText infrastructure. Consent is captured at the point of signing (Web Form opt-in), and every recipient can reply STOP to cancel or HELP for assistance at any time.
- Data minimization
We collect what’s needed to deliver the service and support compliance — not more.
- Policies
Full detail lives in our Privacy Policy and Terms of Service.
Found something? Need something? Talk to a human.
Request our security report or DPA
Need our SOC 2 report, a completed security questionnaire, or a signed Data Processing Agreement for procurement? We'll get it to you.
Go deeper on how we handle compliance.
Need to get security sign-off before you buy?
We’ll send over our SOC 2 report, security questionnaire, or DPA — usually the same business day.