Compliance · SOC 2 Type II

SOC 2 Type II Certified
E-Signature Platform

Zignature's SOC 2 Type II certification means an independent auditor has tested our security, availability, and confidentiality controls over time — not just a point-in-time assessment.

Free plan available · No credit card required · ESIGN Act compliant

SOC 2
Type II certified
Annual
Third-party audit
3
Trust service categories
Available
On request
Key Features

Everything You Need

Built-in features that save time and close deals faster.

Type II Audit

SOC 2 Type II — Tested Over Time, Not Just Point-in-Time

SOC 2 Type I certifications verify controls exist at a single point in time. SOC 2 Type II audits verify that controls operated effectively over an extended period (typically 6-12 months). Zignature's Type II certification provides stronger assurance that our security controls consistently protect your data — not just on audit day.

  • 6-12 month audit period — controls tested for consistent effectiveness over time.
  • Independent AICPA auditor — third-party assurance firm with no conflict of interest.
  • Annual renewal — SOC 2 Type II audit conducted annually for continuous assurance.
Regulatory Requirement
AICPA Trust Services Criteria — CC6 Logical & Physical Access
Implement logical access security software, infrastructure, and architectures over protected information assets to prevent unauthorized access
Authentication mechanisms (including MFA where appropriate) are implemented for all system access to production data
Access to production systems is restricted to authorized personnel using least-privilege principles
Zignature satisfies this requirement
Trust Categories

Security, Availability, and Confidentiality

Zignature's SOC 2 report covers three Trust Service Criteria: Security (CC criteria) — ensuring the system is protected against unauthorized access; Availability — ensuring the system is accessible for operation and use as committed; Confidentiality — ensuring information designated as confidential is protected.

  • Security (CC) — common criteria for protection against unauthorized access.
  • Availability — system accessible per agreed uptime and performance commitments.
  • Confidentiality — confidential customer data handled per documented policies.
Regulatory Requirement
AICPA Trust Services Criteria — A1 Availability
The availability and performance of the system meet the entity's defined objectives and commitments
Environmental, regulatory, and technological changes affecting system availability are identified and monitored
Recovery procedures and business continuity plans are tested to ensure systems can recover from failures within committed timeframes
Zignature satisfies this requirement
Enterprise Trust

Share the SOC 2 Report with Your Security Team

Enterprise and regulated-industry customers often require vendor SOC 2 reports as part of their vendor risk management process. Zignature provides the full SOC 2 Type II report summary to customers under NDA, and answers security questionnaires based on the audit findings — simplifying your vendor approval process.

  • Report available on request — full SOC 2 Type II report shared under NDA.
  • Security questionnaire support — help completing vendor security questionnaires from the SOC 2 findings.
  • Penetration test summary — annual penetration test results available to enterprise customers.
Regulatory Requirement
AICPA Trust Services Criteria — C1 Confidentiality
Confidential information is identified and classified throughout its collection, creation, storage, and processing lifecycle
Confidential information is protected from unauthorized disclosure during all phases of its lifecycle
Confidentiality commitments are communicated to relevant parties and monitored for compliance
Zignature satisfies this requirement
Use Cases

Works for Every Scenario

From simple agreements to complex multi-party workflows.

Enterprise Vendor Risk Management

Security teams at enterprise customers require SOC 2 reports before approving new SaaS vendors — Zignature provides the report on request.

Healthcare HIPAA Vendor Approval

Healthcare organizations often require SOC 2 Type II as part of HIPAA vendor evaluation, alongside the BAA.

Financial Services Vendor Due Diligence

Banks, wealth managers, and insurance companies require SOC 2 reports to satisfy OCC, FINRA, and SEC vendor oversight requirements.

Government & Public Sector

Government contractors and agencies increasingly require SOC 2 as a baseline security certification for cloud service vendors.

Startup Series B+ Due Diligence

Investors conducting technical due diligence on startups often require key vendor SOC 2 reports — Zignature's certificate supports your fundraising process.

ISO 27001 Complementary Controls

Organizations pursuing ISO 27001 certification can use Zignature's SOC 2 as evidence of controls applied by their document signing vendor.

How It Works

Up and Running in Minutes

No training required. Send your first document today.

1

Choose Your Template

Pick from pre-built compliant templates or upload your own document — our system applies the right compliance rules automatically.

2

Configure Compliance Settings

Enable HIPAA BAA, GDPR DPA, identity verification, or QES as required for your regulatory environment.

3

Send to Signers

Recipients get a secure link and are guided through the signing process with all required disclosures and consent flows.

4

Archive with Full Audit Trail

Every transaction is sealed with a tamper-proof certificate of completion — ready for audits, regulators, and legal proceedings.

Compliance Checklist

Does Zignature Check Every Box?

Here's exactly how Zignature satisfies each specific regulatory requirement — with citations.

Requirement Regulation Citation How Zignature Satisfies It Met
Security Controls (CC6 Series) CC6.1–CC6.8 Access controls, encryption at rest and in transit, pen testing
Change Management (CC8) CC8.1 Formal change management with testing and approval procedures
Risk Assessment (CC3) CC3.1–CC3.4 Annual risk assessment, threat monitoring, and vulnerability management
Availability (A1) A1.1–A1.3 99.9% uptime SLA with documented and tested recovery plan
Confidentiality (C1) C1.1–C1.2 Confidential data classified and protected at all lifecycle stages

Enterprise-Grade Security for Your Signatures

SOC 2 Type II certified. Trusted by healthcare, finance, and enterprise teams.

Frequently Asked Questions

Everything you need to know.

What is SOC 2 Type II certification?

SOC 2 (System and Organization Controls 2) is a framework developed by the American Institute of CPAs (AICPA) for assessing the security controls of service organizations. Type II certification means the auditor has not only verified that controls are designed appropriately (Type I) but also tested that those controls operated effectively over an extended period — typically 6-12 months.

What Trust Service Criteria does Zignature's SOC 2 cover?

Zignature's SOC 2 Type II report covers Security (Common Criteria), Availability, and Confidentiality. Security is the foundational criterion required for all SOC 2 reports. Availability covers system uptime and performance commitments. Confidentiality covers protection of information designated as confidential by customers.

Can I request Zignature's SOC 2 report?

Yes. Enterprise and business customers can request Zignature's SOC 2 Type II report summary under a mutual NDA. Contact security@zignature.io or reach out through the enterprise sales team to initiate the report sharing process. Report request turnaround is typically 2-3 business days.

Does SOC 2 certification mean Zignature is HIPAA compliant?

SOC 2 and HIPAA are separate frameworks. SOC 2 verifies general security controls. HIPAA compliance requires specific healthcare data handling practices and a signed Business Associate Agreement. Zignature is both SOC 2 Type II certified and HIPAA compliant — both certifications are needed for healthcare use cases.

How often is Zignature's SOC 2 audit renewed?

Zignature's SOC 2 Type II audit is conducted annually by an independent AICPA-accredited audit firm. Each annual audit covers a 12-month audit period, providing continuous assurance that controls have operated effectively throughout the year. Customers can request the current year's report and prior year's report for trend analysis.

Does Zignature have a penetration test?

Yes. Zignature conducts annual third-party penetration testing of its application and infrastructure. A summary of penetration test findings and remediation actions is available to enterprise customers alongside the SOC 2 report, upon request and under NDA.

Does SOC 2 cover Zignature's subprocessors (AWS, etc.)?

Zignature's SOC 2 report includes its reliance on AWS infrastructure, which is itself SOC 2 Type II certified. The Zignature report documents the controls Zignature implements above AWS's infrastructure controls — creating a complete control stack from infrastructure to application.

Can Zignature complete our security questionnaire?

Yes. Zignature's security team will complete standard vendor security questionnaires using the SOC 2 audit findings as the evidence base. Common questionnaire frameworks (SIG, VSA, CIS, CAIQ) are supported. Contact security@zignature.io to initiate the questionnaire completion process.

Related Resources