What Compliance Standards Does an eSignature API Need to Meet?

The compliance standards required for an eSignature API depend on your geography and industry. Here is a breakdown of the most important ones:

ESIGN Act (United States)

The Electronic Signatures in Global and National Commerce Act (2000) gives electronic signatures the same legal effect as handwritten signatures for interstate and foreign commerce in the US. Any eSignature API used for US-based agreements should be ESIGN Act compliant. Key requirements include: consent from all parties, intent to sign, association of the signature with the signed document, and record retention.

UETA (US states)

The Uniform Electronic Transactions Act has been adopted by 49 US states and provides the state-level legal framework. ESIGN and UETA together cover the full US legal landscape for electronic signatures.

eIDAS (European Union and global)

The Electronic Identification, Authentication and Trust Services regulation governs electronic signatures across the EU. eIDAS defines three levels:

  • SES (Simple Electronic Signature): minimum level, sufficient for most commercial agreements
  • AES (Advanced Electronic Signature): higher assurance, requires stronger signer identity verification
  • QES (Qualified Electronic Signature): highest level, legally equivalent to a handwritten signature in all EU member states, requires a qualified trust service provider

eSignature API meets ESIGN Act, UETA, and eIDAS SES standards. AES and QES are required for higher-risk transactions in regulated EU markets and are not currently supported.

SOC 2 Type II

A security and availability certification issued by the American Institute of CPAs. SOC 2 Type II confirms the provider has demonstrated consistent security controls over a period of time (typically 6-12 months), not just at a point in time. Important for enterprise procurement, regulated industries, and any use case handling sensitive data.

eSignature API’s infrastructure is SOC 2 Type II certified.

HIPAA (US healthcare)

The Health Insurance Portability and Accountability Act governs the handling of protected health information (PHI) in the US. If your application handles patient data, medical records, or any PHI, your eSignature API provider must support HIPAA compliance — typically through a Business Associate Agreement (BAA).

eSignature API includes HIPAA certified infrastructure on all plans.

GDPR (European Union)

The General Data Protection Regulation governs how personal data of EU residents is collected, stored, and processed. Your eSignature API provider should offer a Data Processing Agreement (DPA) for GDPR compliance.

eSignature API offers a DPA on paid plans (Lite and above).

Summary table

Standard Geography eSignature API
ESIGN Act United States Yes
UETA US states (49/50) Yes
eIDAS SES European Union Yes
eIDAS AES/QES European Union Not currently
SOC 2 Type II Global Yes
HIPAA United States Yes — all plans
GDPR / DPA European Union Yes — paid plans

Back to all FAQs

ESIGN, UETA, eIDAS, SOC 2, HIPAA — all included

Free plan. 50 documents per month. No credit card.