Compliance · SOC 2 Type II

SOC 2 Type II Certified
E-Signature Platform

Zignature's SOC 2 Type II certification means an independent auditor has tested our security, availability, and confidentiality controls over time — not just a point-in-time assessment.

Free plan available · No credit card required · ESIGN Act compliant

SOC 2
Type II certified
Annual
Third-party audit
3
Trust service categories
Available
On request
Key Features

Everything You Need

Built-in features that save time and close deals faster.

Type II Audit

SOC 2 Type II — Tested Over Time, Not Just Point-in-Time

SOC 2 Type I certifications verify controls exist at a single point in time. SOC 2 Type II audits verify that controls operated effectively over an extended period (typically 6-12 months). Zignature's Type II certification provides stronger assurance that our security controls consistently protect your data — not just on audit day.

  • 6-12 month audit period — controls tested for consistent effectiveness over time.
  • Independent AICPA auditor — third-party assurance firm with no conflict of interest.
  • Annual renewal — SOC 2 Type II audit conducted annually for continuous assurance.

SOC 2 Type II — Tested Over Time, Not Just Point-in-Time

SOC 2 Type I certifications verify controls exist at a single point in time. SOC 2 Type II audits verify that controls o...

Included on all plans
Trust Categories

Security, Availability, and Confidentiality

Zignature's SOC 2 report covers three Trust Service Criteria: Security (CC criteria) — ensuring the system is protected against unauthorized access; Availability — ensuring the system is accessible for operation and use as committed; Confidentiality — ensuring information designated as confidential is protected.

  • Security (CC) — common criteria for protection against unauthorized access.
  • Availability — system accessible per agreed uptime and performance commitments.
  • Confidentiality — confidential customer data handled per documented policies.

Security, Availability, and Confidentiality

Zignature's SOC 2 report covers three Trust Service Criteria: Security (CC criteria) — ensuring the system is protected ...

Included on all plans
Enterprise Trust

Share the SOC 2 Report with Your Security Team

Enterprise and regulated-industry customers often require vendor SOC 2 reports as part of their vendor risk management process. Zignature provides the full SOC 2 Type II report summary to customers under NDA, and answers security questionnaires based on the audit findings — simplifying your vendor approval process.

  • Report available on request — full SOC 2 Type II report shared under NDA.
  • Security questionnaire support — help completing vendor security questionnaires from the SOC 2 findings.
  • Penetration test summary — annual penetration test results available to enterprise customers.

Share the SOC 2 Report with Your Security Team

Enterprise and regulated-industry customers often require vendor SOC 2 reports as part of their vendor risk management p...

Included on all plans
Use Cases

Works for Every Scenario

From simple agreements to complex multi-party workflows.

Enterprise Vendor Risk Management

Security teams at enterprise customers require SOC 2 reports before approving new SaaS vendors — Zignature provides the report on request.

Healthcare HIPAA Vendor Approval

Healthcare organizations often require SOC 2 Type II as part of HIPAA vendor evaluation, alongside the BAA.

Financial Services Vendor Due Diligence

Banks, wealth managers, and insurance companies require SOC 2 reports to satisfy OCC, FINRA, and SEC vendor oversight requirements.

Government & Public Sector

Government contractors and agencies increasingly require SOC 2 as a baseline security certification for cloud service vendors.

Startup Series B+ Due Diligence

Investors conducting technical due diligence on startups often require key vendor SOC 2 reports — Zignature's certificate supports your fundraising process.

ISO 27001 Complementary Controls

Organizations pursuing ISO 27001 certification can use Zignature's SOC 2 as evidence of controls applied by their document signing vendor.

How It Works

Up and Running in Minutes

No training required. Send your first document today.

1

Choose Your Template

Pick from pre-built compliant templates or upload your own document — our system applies the right compliance rules automatically.

2

Configure Compliance Settings

Enable HIPAA BAA, GDPR DPA, identity verification, or QES as required for your regulatory environment.

3

Send to Signers

Recipients get a secure link and are guided through the signing process with all required disclosures and consent flows.

4

Archive with Full Audit Trail

Every transaction is sealed with a tamper-proof certificate of completion — ready for audits, regulators, and legal proceedings.

Enterprise-Grade Security for Your Signatures

SOC 2 Type II certified. Trusted by healthcare, finance, and enterprise teams.

Frequently Asked Questions

Everything you need to know.

What is SOC 2 Type II certification?

SOC 2 (System and Organization Controls 2) is a framework developed by the American Institute of CPAs (AICPA) for assessing the security controls of service organizations. Type II certification means the auditor has not only verified that controls are designed appropriately (Type I) but also tested that those controls operated effectively over an extended period — typically 6-12 months.

What Trust Service Criteria does Zignature's SOC 2 cover?

Zignature's SOC 2 Type II report covers Security (Common Criteria), Availability, and Confidentiality. Security is the foundational criterion required for all SOC 2 reports. Availability covers system uptime and performance commitments. Confidentiality covers protection of information designated as confidential by customers.

Can I request Zignature's SOC 2 report?

Yes. Enterprise and business customers can request Zignature's SOC 2 Type II report summary under a mutual NDA. Contact security@zignature.io or reach out through the enterprise sales team to initiate the report sharing process. Report request turnaround is typically 2-3 business days.

Does SOC 2 certification mean Zignature is HIPAA compliant?

SOC 2 and HIPAA are separate frameworks. SOC 2 verifies general security controls. HIPAA compliance requires specific healthcare data handling practices and a signed Business Associate Agreement. Zignature is both SOC 2 Type II certified and HIPAA compliant — both certifications are needed for healthcare use cases.

How often is Zignature's SOC 2 audit renewed?

Zignature's SOC 2 Type II audit is conducted annually by an independent AICPA-accredited audit firm. Each annual audit covers a 12-month audit period, providing continuous assurance that controls have operated effectively throughout the year. Customers can request the current year's report and prior year's report for trend analysis.

Does Zignature have a penetration test?

Yes. Zignature conducts annual third-party penetration testing of its application and infrastructure. A summary of penetration test findings and remediation actions is available to enterprise customers alongside the SOC 2 report, upon request and under NDA.

Does SOC 2 cover Zignature's subprocessors (AWS, etc.)?

Zignature's SOC 2 report includes its reliance on AWS infrastructure, which is itself SOC 2 Type II certified. The Zignature report documents the controls Zignature implements above AWS's infrastructure controls — creating a complete control stack from infrastructure to application.

Can Zignature complete our security questionnaire?

Yes. Zignature's security team will complete standard vendor security questionnaires using the SOC 2 audit findings as the evidence base. Common questionnaire frameworks (SIG, VSA, CIS, CAIQ) are supported. Contact security@zignature.io to initiate the questionnaire completion process.

Related Resources

Related Resources