Supported Compliance Standards in BoldSign
BoldSign supports multiple security, privacy, and compliance standards to help organizations meet regulatory, legal, and data protection requirements. This article provides an overview of the compliance standards and certifications supported by BoldSign.
Supported compliance standards
BoldSign supports the following compliance standards and regulations:
Data Residency
- BoldSign allows organizations to store and process documents and signer data within a selected data center region. This helps meet data sovereignty requirements and comply with regional regulations.
For more information, refer to the Data Residency and Regional Compliance policy
HIPAA Compliance
- BoldSign supports HIPAA compliance for organizations that handle Protected Health Information (PHI). HIPAA mode can be enabled to apply safeguards that align with HIPAA requirements.
For more information, refer to the HIPAA Overview
PCI DSS
- BoldSign uses a PCI DSS-certified payment provider to process payment transactions securely. Payment information is protected through industry-standard security controls and encryption.
For more information, refer to the PCI DSS policy
CCPA & CPRA
- BoldSign supports compliance with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). These regulations provide individuals with greater control over their personal information and establish privacy-related obligations for businesses.
For more information, refer to the CCPA and CPRA Privacy policy
SOC 2 Type II
- BoldSign has completed a SOC 2 Type II audit. The audit evaluates controls related to security, availability, confidentiality, and processing integrity.
For more information, refer to the SOC 2 overview
UETA & ESIGN
- Electronic signatures created through BoldSign comply with the Electronic Signatures in Global and National Commerce (ESIGN) Act and the Uniform Electronic Transactions Act (UETA) in the United States.
For more information, refer to the UETA & ESIGN Act Compliance policy
eIDAS (SES)
- BoldSign supports Simple Electronic Signatures (SES) in accordance with the European Union’s eIDAS Regulation (EU No. 910/2014).
For more information, refer to the SES policy
eIDAS (QES)
- BoldSign supports Qualified Electronic Signatures (QES) for organizations that require the highest level of assurance under the eIDAS framework. QES must be enabled before it can be used in signing workflows.
- To request access to QES, contact the BoldSign Support team.
For more information, refer to the QES Overview
Access compliance settings
To view compliance page:
- Go to
Settings. - Select
Compliance.
Contact support
If you require compliance documentation or have questions about a specific compliance standard or certification, contact the BoldSign Support team. When submitting your request, include details about the compliance requirement and any documentation you need.