Electronic signing for contracts and approvals, run in Switzerland, the EU or your own datacentre, with the sealed PDFs and their audit trails on storage you name. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.
- Licence
- AGPL-3.0
- Runs on
- Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
- Upgrades
- Pinned, tested against your configuration, applied in your window
- Upstream
- documenso.com
Running Documenso in production: what it takes
Pin and deploy with its dependencies
A version we have run, on PostgreSQL, with PDFs in an S3-compatible bucket and background jobs on Redis instead of the default in-database queue, which upstream does not recommend for production. Telemetry to Documenso is switched off.
Install and watch the signing certificate
The .p12 that seals every completed document sits in a secret store, mounted read-only. Documenso starts without a working certificate and fails only when a document is completed, so we test signing at deploy and alert on the expiry date weeks ahead. A timestamp authority keeps signatures verifiable after the certificate expires.
Put senders behind sign-on
Your staff sign in through Keycloak or your own IdP over OpenID Connect, with password sign-up switched off. People who only sign need no account.
Back up the data, the certificate and the keys
The database and the bucket go offsite daily, encrypted. The certificate, its passphrase and the encryption keys are backed up separately. Once a month we restore everything into a scratch environment and check that a sealed PDF validates.
Upgrade with the backup as the way back
Documenso runs its database migrations when the new container starts, and they cannot be reversed automatically. Each release runs on a copy first. Once you approve it, the Pilae Agent applies it in your window, with the backup taken just before as the rollback.
What Documenso is, and who runs it
Self-hosted Documenso for contracts and approvals
Documenso sends a PDF out for signature and brings it back sealed. You upload the document, place signature, date and text fields, add recipients as signers, approvers or viewers, and set the order they sign in. Each recipient gets an email link and signs in the browser without an account. When the last one finishes, Documenso seals the PDF with a certificate and adds a page recording who viewed and signed, when, and from which IP address. The full audit log can be appended as well, or downloaded on its own. Templates, direct signing links, a REST API and webhooks cover the documents you send every week.
It replaces DocuSign or Adobe Acrobat Sign for employment contracts, NDAs, supplier agreements and internal approvals. The reason to run it yourself is where those documents and their audit trails end up. It runs on a dedicated machine on your premises or in the Pilae Cloud region you name: Zurich if the contracts must stay in Switzerland, or one of five EU regions, among 12 in all. For the PDF work before a document goes out, such as merging, OCR or redaction, Stirling PDF runs beside it.
Documenso in production: signing certificate, email and audit trail
The part that needs looking after is the signing certificate. Documenso seals every completed document with one .p12 certificate that belongs to the instance, and it ships without one. We install it, keep it and its passphrase in a secret store, and treat its expiry date like a contract renewal. Mail is the other dependency. A request that lands in spam holds up the contract it carries, so the sender domain gets SPF and DKIM before go-live. A completed document cannot be modified, and the sealed PDF and its audit log are the record you keep, so storage is sized for your retention period rather than for this year’s volume.
Envelopes and the audit log sit in PostgreSQL and the PDFs in an S3-compatible bucket, with background jobs on Redis. Staff sign in through Keycloak or your own IdP. The signing pages go out through the one gate on port 443, because outside signers must reach them; the database, bucket and queue stay on your private network. Probes check the health endpoint every 60 seconds and alert an engineer. Backups run daily, encrypted, to an offsite location in your chosen country, with the certificate and keys kept apart, and once a month all of it is restored into a scratch environment. Upgrades go through the Pilae Agent, tested on a copy and applied in your window.
Documenso licence, editions and qualified signatures
The Community Edition has no per-user or per-document fee on your own infrastructure, and it signs at the simple level. For a qualified signature under eIDAS or ZertES, a qualified trust service provider has to verify the signer and hold the key, and Documenso on its own is not one. We tell you which edition and which signature level your documents need before deployment. Our operation is priced on request. Talk to us about the documents you send for signature.
Documenso system requirements
Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.
- CPU and memory
- 2 vCPU · 4 GBUpstream recommends at least two cores and 2 GB for production. The rest is headroom for Redis and for rendering and sealing large PDFs.
- Database
- PostgreSQL 14+The only database Documenso supports. It holds accounts, envelopes, recipients and the audit log, and by default the PDFs as well, which is why we move those to a bucket.
- Signing certificate
- .p12 + passphraseDocumenso ships without one. A self-signed certificate proves the PDF was not altered; one from a CA on the Adobe Approved Trust List also shows as trusted in Acrobat.
- SMTP relay · 587Signing requests, reminders and completion notices all go by email. The sender domain needs SPF and DKIM, or requests land in spam and contracts do not come back.
- Document storage
- S3-compatible bucketFor uploaded and sealed PDFs, with public access blocked. Upstream advises against files over 10 MB in the database, and a bucket keeps the database dump small enough to restore quickly.
Migrating from DocuSign to Documenso
Nothing in DocuSign imports into Documenso. Completed envelopes keep DocuSign's own seal and audit trail, so they are exported as PDFs with their certificates of completion and archived where your records already live, not signed again. Templates are rebuilt, and integrations that call the DocuSign API or wait for its webhooks are rewritten against the Documenso API and webhooks. Those two are the real work. Before any of it, we check whether a process relies on an advanced or qualified signature, because the Community Edition signs at the simple level.
List templates, integrations and signature levels
Templates used in the last ninety days, the systems that create envelopes through the API, and any process that needs an advanced or qualified signature. That last list decides the edition and whether a trust service provider is involved.
Export and archive the completed envelopes
Signed PDFs and certificates of completion come out of DocuSign with their metadata and go to your archive. Documenso does not need to hold them.
Rebuild templates and rewire the API
Each template is set up again with its fields, roles and signing order. Integrations move to the Documenso API and webhooks and are tested on a staging instance with test recipients.
Send new envelopes here, let old ones finish
From the cutover date new requests go out from Documenso. Envelopes already out complete in DocuSign, and the account closes once the last one is back and the export has been checked.
What a Documenso restore needs
postgres/documensoaccounts, envelopes and audit trail, 6 GB
- Envelope · Recipient · Fieldwhat is signed, by whom, in which order
- DocumentAuditLogevery view and signature, with time and IP address
- DocumentDatabucket keys for the original and the sealed PDF
- s3://acme-sign-documentsoriginals and sealed PDFs, 240 GB
secrets/documensobacked up apart from the dumps
- signing.p12acme signing certificate, expires 2027-03-31
- NEXT_PRIVATE_SIGNING_PASSPHRASEthe .p12 is unusable without it
- NEXT_PRIVATE_ENCRYPTION_KEYtwo-factor secrets cannot be read without it
- NEXT_PRIVATE_ENCRYPTION_SECONDARY_KEYother stored secrets cannot be read without it
- s3://acme-backupsoffsite, daily, encrypted
What Pilae is responsible for
A pinned version
A version we have run, not whatever latest resolves to that day.
A runbook
What it depends on, how it fails, what to do about it. In your repository.
A restore drill
Backups restored on a schedule. A backup nobody has restored is a file.
A patch window
Security updates in a window you agreed, with a rollback ready.
Someone watching
Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.
- Where it runs
- zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
- Who holds the credentials
- You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
- If you leave
- The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.
What drives the price of running Documenso
Pricing is on request: a fixed price for onboarding, then a monthly price for Documenso, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.
- Instance size
- The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
- High availability
- One machine with tested restores, or a replicated setup that keeps serving when a node fails.
- Storage and backups
- How much data it holds, how long backups are kept, and point-in-time recovery for its database.
- Plan and support
- Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
- Region
- Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
- Sign-on and integrations
- Single sign-on, directory sync, mail relays and the other systems the app has to reach.
Documenso: common questions
Is Documenso open source?
Is a Documenso signature legally valid in Switzerland and the EU?
Where do the documents and audit trails live?
Can people outside our organisation sign?
Can Documenso replace DocuSign?
Also in business
Odoo Community
Open-source ERP for sales, invoicing, inventory, purchasing and manufacturing, operated on your own servers or dedicated machines in Switzerland and the EU.
Replaces SAP Business One, Microsoft Dynamics
Plane
Issues, cycles and roadmaps for engineering and product teams, on dedicated machines in Switzerland, the EU or your own datacentre.
Replaces Jira, Linear
Cal.com
Booking pages synced with your calendars, run on dedicated machines in any of 12 Pilae Cloud regions, six of them in Switzerland and the EU, or your own datacentre, from the MIT-licensed community edition of Cal.com.
Replaces Calendly
Bring us your Documenso. We will tell you what it takes.
Thirty minutes on the deployment you already have, or the one you are about to start.