Skip to content
Independently verified · Quarterly re-audit
EU VETTED
INSIGHT

The state of US exposure in European e-signature, 2026

We verified 7 European e-signature platforms against their published sub-processor lists and ownership records. 1 operates with no US exposure anywhere in the document and evidence path.

By EU Vetted Editorial Published DISCLOSURE Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.

Of 7 European e-signature platforms, 1 is fully clear of US exposure

We checked every e-signature platform in our directory against its own published sub-processor list, DPA and ownership records, and classified each on our four-level CLOUD Act exposure scale (none, minor, material, direct). The July 2026 re-verification changed this category noticeably: two qualified trust service providers that read as clean in marketing terms, Signaturit and Universign, moved to material once their group ownership and platform sub-processor annexes were read against primary sources.

CLOUD Act exposure Platforms
None 1
Minor 1
Material 4
Direct 1
Any exposure 6

Every platform, and where the exposure enters

Platform Country Ownership Hosting CLOUD Act exposure Where it enters
Skribble Switzerland Other Switzerland None Swiss entity, qualified signatures anchored by Swisscom under both ZertES and eIDAS; no US layer documented in the document or evidence path
Yousign France EU HQ, US-funded France Minor French ANSSI-supervised QTSP; the caveat sits in the cap table, where a US growth-equity firm led the 2021 Series A
Universign France EU HQ, US-funded France Material Now part of Signaturit Group (Namirial), whose parent was acquired by Bain Capital (US) in 2025; the shared platform stores data at rest on AWS, with Twilio and SendGrid for OTP and email
Signaturit Spain EU HQ, US-funded Spain Material Group co-controlled by Bain Capital and PSG Equity (both US private equity); the platform DPA lists AWS at rest (EU region) plus Twilio and SendGrid
Signicat Norway Other EEA (multi-cloud) Material All-EU/EEA corporate chain, but the platform runs multi-cloud on Google Cloud, AWS and Azure (EEA residency), with Mailchimp used for some notifications
Tresorit eSign Switzerland Other Ireland Material Owned by Swiss Post, zero-knowledge encryption throughout, but at-rest storage sits on Microsoft Azure (EU region); qualified certificates come via Evrotrust (Bulgaria)
Eversign Austria US-owned United States Direct Acquired by Apryse (Denver, US) in 2022 and rebranded Xodo Sign; the operating company answers to a US parent

The pattern is consistent with what we see across the whole directory: the flag on the website is rarely where the exposure comes from. E-signature is actually the category where Europe holds a structural legal advantage, because a qualified electronic signature can only be issued through a trust service provider supervised in an EU member state (or its Swiss ZertES equivalent). The qualified trust layer is European by construction.

The exposure enters around that layer. Documents wait in storage before and after signing, audit trails and evidence files accumulate, signature requests go out by email, one-time passwords go out by SMS, and identity checks call external providers. Each of those steps can sit with a US-incorporated processor regardless of where the signature certificate comes from. And ownership matters on its own: the 2025 consolidation of the Signaturit Group under Namirial brought two US private-equity firms into control of what used to read as a purely European QTSP portfolio, which is what moved both Signaturit and Universign in our July 2026 re-verification.

Our four-level classification records whether customer data could fall under US extraterritorial reach: none (EU/EEA/Swiss operator, no US parent, no notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest staying in the EU), material (a US parent or US-owned hyperscaler in the core data path), and direct (the operator itself is US-incorporated). For e-signature the data path we read is specific: document storage before and after signing, the audit-trail and evidence layer, OTP and email delivery, and identity verification.

Sources are the vendors' own published documents: sub-processor lists, DPA annexes and ownership records, re-checked quarterly. Every figure and verdict on this page renders live from the dataset, so the page updates when a re-verification changes a classification. The cross-category picture is in our CLOUD Act exposure analysis; the platforms that clear the strictest bar are listed on e-signature without US sub-processors; all listings with per-platform detail are on the e-signature category page.

The figures on this page may be republished with attribution. Cite as "Source: EU Vetted, verified July 2026" and link to this page. Numbers render live from our dataset and change when a quarterly re-verification changes a classification, so the link, not a copied figure, is the durable reference.

Frequently asked questions

Which European e-signature platforms have no US sub-processors in 2026?
Of the 7 European platforms we verified, 1 operates with no US parent and no US-incorporated sub-processor in the document, evidence and delivery path: Skribble (Switzerland, CLOUD Act exposure None). The full per-platform breakdown, including where the exposure enters for the others, is in the table on this page.
Can a European e-signature vendor still fall under the US CLOUD Act?
Yes. The qualified trust layer is European by law under eIDAS, but document storage, audit-trail hosting, OTP delivery and identity checks often run on US-owned infrastructure, and US ownership or funding of the vendor itself also counts. That is why 6 of 7 platforms in this snapshot carry some exposure.
How is this data verified and how often is it updated?
Each platform is checked against its own published sub-processor list, DPA and ownership records, and re-verified quarterly. Figures on this page render live from the dataset, so they update when a re-verification changes a classification.
METHODOLOGY

For every product we read the public DPA, sub-processors document, hosting region declaration, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.

Read methodology →