Tresorit eSign
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
E-signature module of Swiss-Post-owned Tresorit, the directory's only zero-knowledge E2E option with eIDAS Qualified signatures (via Evrotrust QTSP); runs on Azure (default EU region Ireland).
Tresorit eSign offers EU hosting in Ireland, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under E-signature.
Assessment notes
Tresorit eSign is the electronic-signature module of Tresorit AG (Zurich; sole shareholder Swiss Post, the Swiss state-owned operator) and is the directory's only e-signature option combining zero-knowledge end-to-end encryption with eIDAS Qualified Electronic Signatures, the latter issued through a partnership with the EU Qualified Trust Service Provider Evrotrust (Bulgaria) rather than by Tresorit itself; ISO/IEC 27001:2022 certified, runs on Microsoft Azure with a default EU storage region of Ireland and customer-selectable EU residency. CLOUD Act exposure is material because Azure is a US-owned hyperscaler in the at-rest path, but the zero-knowledge architecture means Azure holds ciphertext only and Tresorit holds no keys; held at 4/5 by that US storage sub-processor and the absence of a public standalone DPA URL (request-based), with state-anchored Swiss-Post ownership and the E2E + QES combination as the offsetting strengths. For pure-EU-sovereignty buyers the one category option with no US-owned provider in the at-rest path is Skribble (CH), whose signed documents sit with cloudscale.ch, VSHN and IONOS, though its overall exposure is now recorded as Minor after Cloudflare appeared in its published chain; the Namirial-group QTSPs (Universign FR, Signaturit ES) are no longer a cleaner alternative here, since their 2025 Bain Capital (US private-equity) ownership and AWS-at-rest hosting put them at material too, without Tresorit's zero-knowledge mitigation.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 10 · 7 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: No
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Tresorit eSign
Tresorit eSign is the electronic-signature module of Tresorit AG (Pfingstweidstrasse 60b, 8005 Zurich; CHE-349.825.210), the zero-knowledge end-to-end-encrypted cloud-storage company that has been a wholly-owned subsidiary of Swiss Post (the Swiss state-owned postal and digital-services operator) since 2021. Launched as a product around 2022, eSign is the directory's only e-signature listing that combines genuine zero-knowledge, end-to-end encryption of the document workflow with full eIDAS Qualified Electronic Signatures (QES). Tresorit is not itself a Qualified Trust Service Provider; the QES tier is issued through a partnership with Evrotrust, an EU-listed QTSP (Bulgaria), and obtaining a qualified signature requires ID/passport plus video identification of the signer, in line with eIDAS. The product also offers simple electronic signatures, Long Term Validation (signature validity guaranteed for 5, 10, or more years), drag-and-drop fillable fields, and signing from any device without a Tresorit account.
For an EU-sovereignty audit the posture mirrors Tresorit's storage listing. The infrastructure is Microsoft Azure, with the default data-at-rest region in Ireland (EU) and customer-selectable EU residency (Germany, France, Netherlands and others) on Business and Enterprise plans; the company is ISO/IEC 27001:2022 certified (TÜV Rheinland) and aligned with GDPR plus a broad regulated-industry set. The directory records cloud_act_exposure: material because Azure is a US-owned hyperscaler sitting in the at-rest path, but the zero-knowledge architecture means Azure stores ciphertext only and Tresorit holds no keys, so compelled disclosure yields no readable content. The two transparency gaps carried over from the storage listing apply here too: there is no public standalone DPA URL (the DPA is delivered to business customers on request) and the sub-processor list is published via the Tresorit help centre rather than a dedicated legal page. Ownership is Swiss-state-anchored (ownership_signal: other: Switzerland, with Swiss Post as sole shareholder).
Pricing is paid: licences are around €5/month per user, with per-signature pricing of roughly €0.3 for a simple electronic signature and €2.5 for an EU Qualified electronic signature, and a small free quota (about 10 simple and 6 qualified signatures) for evaluation. Best fit: regulated teams (legal, healthcare, finance, security-conscious businesses) already standardised on Tresorit's encrypted storage who want qualified signatures inside the same end-to-end-encrypted workspace rather than bolting on a separate signing platform. Buyers whose priority is the cleanest ownership-and-sub-processor story for purely-EU workflows should look to Skribble (Switzerland), whose signed documents sit with Swiss and German providers, though its overall CLOUD Act exposure is now recorded as Minor since Cloudflare entered its published chain; the Namirial-group QTSPs Universign (France) and Signaturit (Spain), once the benchmark here, now carry the same material exposure (AWS at rest) plus a US-private-equity parent (Bain Capital, 2025) and, unlike Tresorit eSign, no zero-knowledge encryption to offset it. Tresorit eSign's differentiator remains the zero-knowledge-encryption-plus-QES combination, which none of the other listed options match.
Sub-processor map · 10
-
Amazon Simple Email Service (SES) USUnited States
Transactional and notification emails (data in Ireland/EU)
-
Microsoft Azure USUnited States
Primary hosting (E2E-encrypted content stored in Ireland/EU) and application performance monitoring
-
SendGrid (Twilio) USUnited States
Transactional and notification emails
-
Stripe USUnited States
Payment processing
-
Twilio USUnited States
Two-factor authentication (voice and SMS)
-
Zendesk USUnited States
Customer support tools
-
Zuora USUnited States
Subscription billing, invoicing and management
-
Evrotrust Technologies AD EUBulgaria
EU Qualified Trust Service Provider; issuance of eIDAS Qualified Electronic Signatures and signer identity verification
-
Tresorit GmbH EUGermany
Affiliate sub-processor delivering Tresorit services
-
Tresorit Kft. EUHungary
Affiliate sub-processor delivering Tresorit services
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Simple Email Service (SES) | United States | Transactional and notification emails (data in Ireland/EU) | US |
| Microsoft Azure | United States | Primary hosting (E2E-encrypted content stored in Ireland/EU) and application performance monitoring | US |
| SendGrid (Twilio) | United States | Transactional and notification emails | US |
| Stripe | United States | Payment processing | US |
| Twilio | United States | Two-factor authentication (voice and SMS) | US |
| Zendesk | United States | Customer support tools | US |
| Zuora | United States | Subscription billing, invoicing and management | US |
| Evrotrust Technologies AD | Bulgaria | EU Qualified Trust Service Provider; issuance of eIDAS Qualified Electronic Signatures and signer identity verification | EU |
| Tresorit GmbH | Germany | Affiliate sub-processor delivering Tresorit services | EU |
| Tresorit Kft. | Hungary | Affiliate sub-processor delivering Tresorit services | EU |
Source: the vendor’s published sub-processor list, read 26 Jun 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of Tresorit eSign
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Austria · $10/moUS-LinkedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
SpainEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
NorwayEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
US-Linked | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
$10/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |