TRUST CENTER

Built for operators who can't afford a signature that doesn't hold up.

OtterSign is independently audited and built to protect the waivers, agreements, and data your business depends on. Here’s an inside look at how we secure your account, your signers, and every document in between.

SOC 2

Type I & Type II

HIPAA

Aligned practices

GDPR · CCPA

CA, NY & CO ready

24/7

Monitoring & support

SOC 2 Type I & II Audited by Thoropass
HIPAA-Aligned Practices, not certification
Privacy Ready GDPR · CCPA · NY · CO
CERTIFICATIONS

Independently audited, not just self-declared.

OtterSign has completed both stages of the SOC 2 audit, verified by an independent third-party auditor.

Type I

SOC 2 Type I

Confirms that OtterSign's security controls were suitably designed at a specific point in time — covering access control, encryption, change management, and monitoring across the platform.

Auditor: Thoropass

SOC 2 Type II

Confirms those same controls operated effectively over an extended observation period — the deeper, ongoing-proof standard enterprise buyers and compliance teams ask for.

Auditor: Thoropass

COMPLIANCE FRAMEWORKS

Waivers and agreements that hold up where it counts.

OtterSign is built around the laws that govern electronic signatures, the privacy rules that govern the data behind them, and the vendor and payment boundaries that keep everything else contained — nationally and in the states with the strictest requirements.

electronic-signatures

ESIGN Act & UETA

The federal ESIGN Act and state-level UETA require four things for a signature to be legally binding: intent to sign, consent to do business electronically, a clear association between the signature and the record, and retention of that record. Every OtterSign signature carries a timestamped audit trail that documents each of these — who signed, what they agreed to, and when.

custom-questions

GDPR

For EU signers and subscribers, OtterSign processes personal data on a lawful basis, collects only what’s needed to deliver the service, and honors requests to access, correct, or delete personal data. Data handling terms for customers processing EU data are set out in our Data Processing Agreement, available on request.

templates

California (CCPA/CPRA)

California residents have the right to know what personal information OtterSign collects, request its deletion, and opt out of its sale or sharing. OtterSign does not sell personal information, and CCPA/CPRA rights requests are honored without requiring account changes that would discriminate against the requester.

safety-videos

New York (SHIELD Act)

New York’s SHIELD Act requires reasonable administrative, technical, and physical safeguards for private information, plus timely breach notification. OtterSign’s encryption, access controls, and incident response process are built around those same requirements.

edit-and-duplicate

Colorado Privacy Act

Colorado residents can access, correct, delete, and obtain a copy of their personal data, and opt out of targeted advertising and profiling. OtterSign limits data collection to what’s needed for the service consistent with the Act’s purpose-limitation requirement.

HIPAA-Aligned Practices

OtterSign follows safeguards modeled on the HIPAA Security Rule’s administrative, physical, and technical categories — encryption, access logging, and workforce training among them. OtterSign is not a HIPAA-certified platform; operators handling protected health information should confirm fit for their specific use case before relying on it as their sole safeguard.

tamper-evident-pdfs

Payments & PCI Scope

OtterSign doesn’t process or store cardholder data directly. Payment collection — including the Digital Access Card flow connecting OtterSign to OtterOrder — hands off to OtterOrder’s checkout, keeping card data out of OtterSign’s systems entirely.

customer-success-team

Third-Party Subprocessors

Vendors that touch customer or signer data — cloud hosting, email delivery, SMS carriers — are reviewed before onboarding and periodically after, and are bound by agreements requiring them to meet OtterSign’s data-handling standards. A current subprocessor list is available on request.

SECURITY PRACTICES

The controls behind the audit.

SOC 2 is the proof; here’s what it’s actually verifying about how we run the platform day to day.

01

Encryption in transit & at rest

Customer and subscriber data is encrypted using TLS in transit and encrypted at rest across our infrastructure.

02

Role-based access control

Internal access to production systems and customer data is scoped by role, logged, and reviewed on a recurring basis.

03

Cloud infrastructure on AWS

Core signing, storage, and messaging infrastructure runs on Amazon Web Services with its own independently audited controls.

04

Continuous monitoring

Systems are monitored around the clock, with alerting tied into an internal incident response process.

05

Vendor & subprocessor review

Third-party vendors that touch customer or signer data are reviewed before onboarding and periodically thereafter.

06

Employee security training

Team members complete security and confidentiality training as part of onboarding and on an ongoing basis.

AUDIT TRAIL

Every signature leaves a defensible trail.

When a document goes out for signature, OtterSign generates a unique record ID for that signing session and attaches a signature certificate to the document itself. That ID can be used to look up exactly who signed, when, and what happened leading up to it — giving you documented proof of access, review, and signature if an agreement is ever challenged.

This applies across every way a document reaches a signer — a shared link, a QR code, a kiosk, or an ID-verified signing flow — and it’s on by default. Nothing extra to configure.

Signature Certificate
Sarah Johnson
IP Address172.104.55.212
LocationBoise, US
Record ID OS-7F3K-91QX-B04E-LM2T

Audit-tracked events include

Document sent

Document viewed

Electronic Record & Signature Disclosure accepted

Signer details captured

ID verification completed (4D Scanning)

Kiosk / QR signing activated

Document signed

Decline to sign, with reason if provided

SMS & marketing consent captured

Not exhaustive — newer signing paths add their own tracked events as they ship.

SIGNER & DATA PROTECTIONS

Compliance your signers can feel, too.

Trust isn’t just an audit report — it’s what happens every time someone signs a waiver, checks in at a kiosk, or asks what happens to their information.

Every signature is backed by the tamper-evident audit trail detailed above — timestamp, record ID, and signer identity, so it can be verified later if it’s ever challenged.

SMS automation runs on OtterText infrastructure. Consent is captured at the point of signing (Web Form opt-in), and every recipient can reply STOP to cancel or HELP for assistance at any time.

We collect what’s needed to deliver the service and support compliance — not more.

Full detail lives in our Privacy Policy and Terms of Service.

RESPONSIBLE DISCLOSURE

Found something? Need something? Talk to a human.

Report a security issue

If you believe you've found a security vulnerability affecting OtterSign, we want to hear from you directly before it goes anywhere else.

Request our security report or DPA

Need our SOC 2 report, a completed security questionnaire, or a signed Data Processing Agreement for procurement? We'll get it to you.

Need to get security sign-off before you buy?

We’ll send over our SOC 2 report, security questionnaire, or DPA — usually the same business day.