Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Eversign (Xodo Sign)

VERIFIED
E-signature · Austria
Founded 2017 · eversign.com ↗

Vienna-launched e-signature platform (eversign GmbH, 2017) — acquired by Apryse (US/PDFTron) in 2022, rebranded as Xodo Sign.

Why this score?

Eversign GmbH (Vienna + London, founded 2017) launched as an EU-based e-signature platform with SOC II + GDPR + eIDAS + UETA attestation — but in 2022 it was acquired by Apryse (formerly PDFTron Systems Inc., headquartered in Denver, Colorado, USA with operations in Vancouver, Canada) and subsequently rebranded as Xodo Sign. Per the directory's strict-ownership stance the resulting product is us_owned with direct CLOUD Act exposure under a US parent; score capped at 3/5 reflecting the legacy Vienna engineering operation, eIDAS-compliant signature workflow, and continuing EU-customer base, but procurement-grade EU buyers should choose Yousign (FR, eIDAS-qualified), Skribble (CH, ZertES + eIDAS), Universign (FR), or Signaturit (ES) instead — all structurally cleaner alternatives in this category.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Eversign (Xodo Sign)

Eversign was originally founded in 2017 as a Vienna-headquartered e-signature platform operating as **eversign GmbH** (Austrian Firmenbuch FN572452t, with offices also in London) — at launch one of the more promising EU-based DocuSign alternatives, with SOC II + GDPR + eIDAS + UETA compliance and a flat developer-API-friendly pricing model. In **2022 the company was acquired by Apryse** (formerly PDFTron Systems Inc.), a US-Canadian document-processing technology group headquartered in Denver, Colorado with operations in Vancouver, Canada — the same Apryse that runs the **Xodo** consumer PDF tools. Post-acquisition, the Eversign product was integrated into the Apryse portfolio and rebranded as **Xodo Sign**; the eversign.com URL persists primarily for SEO continuity and existing customer accounts. For an EU-sovereignty audit the listing now sits firmly outside the procurement-grade tier despite the Austrian engineering heritage. The controlling entity is a US-incorporated parent (Apryse / PDFTron Systems Inc.), which under our strict-ownership stance is `us_owned` with `direct` CLOUD Act exposure. The product retains its eIDAS-compliant signature workflow and Austrian/UK operating presence, but contracts are now with the Apryse-controlled entity rather than with an EU-controlled vendor. Compliance attestations carry through: SOC II / GDPR / eIDAS / UETA. Pricing follows the Apryse-portfolio strategy with transparent per-user / per-document tiers; specific entry-tier EUR figures were not captured at audit. Best fit: existing eversign customers who already have contracts, US-headquartered enterprise buyers using the wider Apryse stack (Xodo / PDFTron). Procurement-grade EU-only buyers should choose **Yousign (France, eIDAS-qualified)**, **Skribble (Switzerland, ZertES + eIDAS)**, **Universign (France, qualified trust service provider)**, or **Signaturit (Spain, eIDAS-qualified Barcelona)** instead — all listed in this category and structurally cleaner under the strict-ownership stance.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications

SOC 2
ACTIVE
Informational · US framework
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
Custom pricing

Contact vendor for tier or volume pricing.

View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    eversign.com/legal…
    Open ↗
ALTERNATIVES

Alternatives in this category