Managed Documenso hosting

BusinessOn-prem or sovereign site

Electronic signing for contracts and approvals, run in Switzerland, the EU or your own datacentre, with the sealed PDFs and their audit trails on storage you name. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about Documenso

Licence
AGPL-3.0
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
documenso.com

Running Documenso in production: what it takes

  1. Pin and deploy with its dependencies

    A version we have run, on PostgreSQL, with PDFs in an S3-compatible bucket and background jobs on Redis instead of the default in-database queue, which upstream does not recommend for production. Telemetry to Documenso is switched off.

  2. Install and watch the signing certificate

    The .p12 that seals every completed document sits in a secret store, mounted read-only. Documenso starts without a working certificate and fails only when a document is completed, so we test signing at deploy and alert on the expiry date weeks ahead. A timestamp authority keeps signatures verifiable after the certificate expires.

  3. Put senders behind sign-on

    Your staff sign in through Keycloak or your own IdP over OpenID Connect, with password sign-up switched off. People who only sign need no account.

  4. Back up the data, the certificate and the keys

    The database and the bucket go offsite daily, encrypted. The certificate, its passphrase and the encryption keys are backed up separately. Once a month we restore everything into a scratch environment and check that a sealed PDF validates.

  5. Upgrade with the backup as the way back

    Documenso runs its database migrations when the new container starts, and they cannot be reversed automatically. Each release runs on a copy first. Once you approve it, the Pilae Agent applies it in your window, with the backup taken just before as the rollback.

What Documenso is, and who runs it

Self-hosted Documenso for contracts and approvals

Documenso sends a PDF out for signature and brings it back sealed. You upload the document, place signature, date and text fields, add recipients as signers, approvers or viewers, and set the order they sign in. Each recipient gets an email link and signs in the browser without an account. When the last one finishes, Documenso seals the PDF with a certificate and adds a page recording who viewed and signed, when, and from which IP address. The full audit log can be appended as well, or downloaded on its own. Templates, direct signing links, a REST API and webhooks cover the documents you send every week.

It replaces DocuSign or Adobe Acrobat Sign for employment contracts, NDAs, supplier agreements and internal approvals. The reason to run it yourself is where those documents and their audit trails end up. It runs on a dedicated machine on your premises or in the Pilae Cloud region you name: Zurich if the contracts must stay in Switzerland, or one of five EU regions, among 12 in all. For the PDF work before a document goes out, such as merging, OCR or redaction, Stirling PDF runs beside it.

Documenso in production: signing certificate, email and audit trail

The part that needs looking after is the signing certificate. Documenso seals every completed document with one .p12 certificate that belongs to the instance, and it ships without one. We install it, keep it and its passphrase in a secret store, and treat its expiry date like a contract renewal. Mail is the other dependency. A request that lands in spam holds up the contract it carries, so the sender domain gets SPF and DKIM before go-live. A completed document cannot be modified, and the sealed PDF and its audit log are the record you keep, so storage is sized for your retention period rather than for this year’s volume.

Envelopes and the audit log sit in PostgreSQL and the PDFs in an S3-compatible bucket, with background jobs on Redis. Staff sign in through Keycloak or your own IdP. The signing pages go out through the one gate on port 443, because outside signers must reach them; the database, bucket and queue stay on your private network. Probes check the health endpoint every 60 seconds and alert an engineer. Backups run daily, encrypted, to an offsite location in your chosen country, with the certificate and keys kept apart, and once a month all of it is restored into a scratch environment. Upgrades go through the Pilae Agent, tested on a copy and applied in your window.

Documenso licence, editions and qualified signatures

The Community Edition has no per-user or per-document fee on your own infrastructure, and it signs at the simple level. For a qualified signature under eIDAS or ZertES, a qualified trust service provider has to verify the signer and hold the key, and Documenso on its own is not one. We tell you which edition and which signature level your documents need before deployment. Our operation is priced on request. Talk to us about the documents you send for signature.

Documenso Community Edition is AGPL-3.0. Code in the packages/ee directory, and the features its FEATURES file lists, are under the Documenso Commercial License and may run in production only under a paid Business Edition or Enterprise Edition licence from Documenso. They include the per-organisation single sign-on portal, re-authentication with a passkey or two-factor code before signing, 21 CFR Part 11 features, custom sender domains, embedded authoring, and signing through a trust service provider over the Cloud Signature Consortium API, which is the route to advanced and qualified signatures. Instance-wide OpenID Connect sign-in is in the Community Edition. A licence key covers one instance and is checked against the Documenso licence server at start-up, then cached. If you need it, the licence is held in your name and the proposal says so.

Documenso system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
2 vCPU · 4 GBUpstream recommends at least two cores and 2 GB for production. The rest is headroom for Redis and for rendering and sealing large PDFs.
Database
PostgreSQL 14+The only database Documenso supports. It holds accounts, envelopes, recipients and the audit log, and by default the PDFs as well, which is why we move those to a bucket.
Signing certificate
.p12 + passphraseDocumenso ships without one. A self-signed certificate proves the PDF was not altered; one from a CA on the Adobe Approved Trust List also shows as trusted in Acrobat.
Mail
SMTP relay · 587Signing requests, reminders and completion notices all go by email. The sender domain needs SPF and DKIM, or requests land in spam and contracts do not come back.
Document storage
S3-compatible bucketFor uploaded and sealed PDFs, with public access blocked. Upstream advises against files over 10 MB in the database, and a bucket keeps the database dump small enough to restore quickly.

Migrating from DocuSign to Documenso

Nothing in DocuSign imports into Documenso. Completed envelopes keep DocuSign's own seal and audit trail, so they are exported as PDFs with their certificates of completion and archived where your records already live, not signed again. Templates are rebuilt, and integrations that call the DocuSign API or wait for its webhooks are rewritten against the Documenso API and webhooks. Those two are the real work. Before any of it, we check whether a process relies on an advanced or qualified signature, because the Community Edition signs at the simple level.

  1. List templates, integrations and signature levels

    Templates used in the last ninety days, the systems that create envelopes through the API, and any process that needs an advanced or qualified signature. That last list decides the edition and whether a trust service provider is involved.

  2. Export and archive the completed envelopes

    Signed PDFs and certificates of completion come out of DocuSign with their metadata and go to your archive. Documenso does not need to hold them.

  3. Rebuild templates and rewire the API

    Each template is set up again with its fields, roles and signing order. Integrations move to the Documenso API and webhooks and are tested on a staging instance with test recipients.

  4. Send new envelopes here, let old ones finish

    From the cutover date new requests go out from Documenso. Envelopes already out complete in DocuSign, and the account closes once the last one is back and the export has been checked.

What a Documenso restore needs

  • postgres/documensoaccounts, envelopes and audit trail, 6 GB
    • Envelope · Recipient · Fieldwhat is signed, by whom, in which order
    • DocumentAuditLogevery view and signature, with time and IP address
    • DocumentDatabucket keys for the original and the sealed PDF
  • s3://acme-sign-documentsoriginals and sealed PDFs, 240 GB
  • secrets/documensobacked up apart from the dumps
    • signing.p12acme signing certificate, expires 2027-03-31
    • NEXT_PRIVATE_SIGNING_PASSPHRASEthe .p12 is unusable without it
    • NEXT_PRIVATE_ENCRYPTION_KEYtwo-factor secrets cannot be read without it
    • NEXT_PRIVATE_ENCRYPTION_SECONDARY_KEYother stored secrets cannot be read without it
  • s3://acme-backupsoffsite, daily, encrypted
An example layout for acme. The PDFs are in the bucket and the audit trail is in PostgreSQL, but the signing certificate and the encryption keys are in neither, so they are backed up separately, as upstream advises for the certificate. The monthly drill restores all of it and checks that a sealed PDF still validates.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running Documenso

Pricing is on request: a fixed price for onboarding, then a monthly price for Documenso, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

Documenso: common questions

Is Documenso open source?

The Community Edition is AGPL-3.0 and covers sending, templates, the API, webhooks, certificate sealing and OpenID Connect sign-in. Code in the packages/ee directory and the features listed there are under the Documenso Commercial License and need a paid Business or Enterprise licence in production: the per-organisation SSO portal, passkey or two-factor re-authentication before signing, 21 CFR Part 11, custom sender domains, embedded authoring and signing through a trust service provider.

Is a Documenso signature legally valid in Switzerland and the EU?

For most contracts, NDAs, approvals and HR documents, yes. Out of the box Documenso produces simple electronic signatures: each signer's action is recorded, and the PDF is sealed with your instance's certificate, not each signer's, so any later change shows. Where the law demands a handwritten signature, only a qualified signature stands in for it: under eIDAS in the EU, and in Switzerland under ZertES together with a qualified timestamp. That needs a qualified trust service provider to verify the signer and hold the key. With a paid licence, Documenso can hand signing to such a provider, for the whole instance at once. Upstream lists ZertES support as planned, so for Swiss qualified signatures we confirm that your provider works with Documenso before anything is promised.

Where do the documents and audit trails live?

The audit trail in PostgreSQL and the sealed PDFs in an S3-compatible bucket, both on dedicated machines in the region you named, in ISO 27001-certified datacentres, or on your own hardware. Telemetry to Documenso is off. If a timestamp authority is configured, it receives only hashes, never the document.

Can people outside our organisation sign?

Yes, and they need no account. They get an email with a link, sign in the browser and receive a completion notice. The signing pages go out through the Pilae gate on port 443, because outside signers have to reach them. The database, the bucket and the job queue stay on your private network.

Can Documenso replace DocuSign?

For signature requests, templates, signing order, reminders, an audit trail and an API, yes. There is no importer for DocuSign templates or envelope history, identity verification of signers is not built in, and advanced or qualified signatures need a paid licence and a trust service provider. We list which of your processes fall into those gaps before the rebuild starts.

Also in business

Back to apps

Bring us your Documenso. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.