Zoho Sign - An electronic signature solution
Zoho Sign is a secure, cloud-based digital signature app that allows businesses to sign documents electronically and execute legally binding digital paperwork. Users can easily create comprehensive e-signature workflows to send documents, verify signer identities, collect payments, trigger reminders, and track their overall status in real-time.
Features
- Electronic document signing and approval with signer authentication, payment collection
- Sophisticated e-signature workflows with signer hierarchy, authentication, and private notes
- Tracking and management of documents online and remote collaboration
- Custom branding, white label, and vernacular signing across 20+ languages
- Customised user management with granular data and document access control
- Detailed reporting, activity tracking, and comprehensive audit trails
- Integrated trust services for document timestamping, identity verification, qualified signatures
- Bulk signing and sending, AI-based field detection and document summarisation
- Templates, self-service signing, and integrations with other popular applications
- APIs, webhooks, and SDKs along with controls for life sciences
Benefits
- Efficiently digitise paperwork with automated signature, approval, and payment collection
- Generate legally binding, compliant business documents ensuring tamper-proof authenticity
- Effortlessly access and manage documents through centralised cloud-based document management
- Ensure non-repudiation through secure, authenticated document delivery for signature collection.
- Ensure secure workflows for enhanced productivity, scalability, and data integrity.
- Achieve complete visibility and access control through customisable reporting features.
- Boost trust and localisation with brand alignment and recipient sensitivity.
- Seamless integration and data flow across apps for enhanced interoperability.
- Accelerate business turnaround with remote execution of paperwork from anywhere
- Increased operational efficiency from significantly lowered administrative and labour costs
Pricing
£10 to £22 a user a month
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
8 0 0 7 5 1 1 2 3 7 1 0 2 4 1
Contact
Zoho Corporation Limited
Sreyas Benjamin
Telephone: +44 2038072092
Email: zohouk-gcloud@eu.zohocorp.com
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Only cloud-based deployment and no support for an on-premise setting. Basic pre-requisites includes a good network connection for easy access, and recommended browser and machine specifications for avoiding uninterrupted compatibility concerns.
- System requirements
-
- Works on latest version of your preferred web browser
- Stable internet connectivity
- JavaScript and firstparty cookies to be enabled on your browser
- App must be downloaded from the marketplace on mobile platforms
- Extenstion must be installed from marketplace on some third-party platforms
- PDF application necessary to ascertain digital signature properties in documents
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- On an average, the response time for free users is 24 hours, for paid 8 hours and for premium support between 1 to 4 hours, 5 days a week. Support is accessible during weekends however response times may be slower for free users.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Zoho Sign offers support in 4 levels.
Basic - Support is free for all Zoho Sign users
Classic - All paid Zoho Sign subscribers
Premium - Subscribers have to pay an additional cost to avail this support which offers faster response time, 24*5 support along with remote assistance, onboarding and configuration assistance.
Enterprise - Everything in premium support along with an enterprise account manager and 24*7 support. Subscriber must have at least 25 user license in the Enterprise plan and can avail an additional on-site support. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Zoho Sign offers a tutorial videos and a complete product overview along with detailed online help documentation via email when users sign up. Users can also choose to register for our monthly webinars, or attend our physical events such as workshops, user conferences, user group meetings, and roadshows to seek personalised assistance or training. We also offer paid one-on-one training and paid implementation assistance along with free product demos which can be availed by filling a booking form on our website.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Mp4
- Pptx
- End-of-contract data extraction
- Zoho Sign offers the option to bulk backup the documents to their choice of cloud storage provider or have the documents downloaded to their local storage.
- End-of-contract process
- Zoho Sign moves the account to ‘Free’ once the subscription gets expired. Upon 6 month of inactivity in the Free account, as per our policy, the user will be notified via email twice following which the account and the associated data will be deleted.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Zoho Sign works in the same way across platform. With the mobile application, users can sign, send, manage documents and track their status in real-time on the go. However, mobile apps are limited to only the core functions of Zoho Sign and do not support all functions available on the web application. Users get notified through push notifications and have the ability to scan physical documents using their device cameras to digitally sign them or send them out for signatures. Users can also take advantage of mobile-only enhancements such as widgets, shortcuts, and biometrics to execute the available functions.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- With Zoho Sign, users can create comprehensive yet easy e-sign workflows to sign documents and send them out to collect signatures, approval, and payments. Zoho Sign can also help authenticate signers and approvers, verify recipient identity, trigger periodic reminders, and track the signature, approval, and payment status of paperwork in real-time. Users can also save workflows and documents into reusable templates for quicker sending, and use it along with additional features such as bulk send, bulk sign, in-person signing, and public form-based self-service methods for increased productivity and efficiency.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Zoho can be accessed via cloud, web application and mobile application. All text content on service is linear, clear and readable. There is minimal usage of audio, video and images, making all the essential modules accessible.
For ease of access the service supports 200% of zoom without loss of content and functionality in our web page. Keyboard shortcuts and hover hints for fields are available out of the box. - Accessibility testing
- We are currently assessing and in the progress of making our product compliant to Accessibility standard WCAG 2.1 AA . In this journey, we are yet to do the testing with the actual users of assistive technology. It will be done when the product becomes compliant to WCAG standard.
- API
- Yes
- What users can and can't do using the API
-
Zoho Sign's APIs will help users integrate Zoho Sign within any application, system, or platform to send, sign, and manage documents right from their respective interface. Zoho Sign API carries a separate pricing wherein documents being sent via API consume our own add-on, Zoho Sign credits, which require separate purchase in addition to licensing costs.
The Zoho Sign API enables you to perform nearly all the operations that you do in the web application. The APIs are built based on the REST principles that are easy to learn and use, reliable, secure, scalable, and offers high performance.
The APIs follow HTTP rules, enabling a wide range of HTTP clients to interact with them. Each function and resource of Zoho Sign is exposed as a URL. The URL of each function or resource can be obtained by accessing the API root endpoint.
The Zoho Sign API uses the OAuth2.0 protocol for authentication. It is an industry-standard protocol specification that enables third-party applications (clients) to gain delegated access to protected resources in Zoho via an API. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Zoho Sign allows the organisation administrators to invite new users to their organisation, add customised branding by redesigning email templates, changing the language and signer vernacular, adding their organisation logo to the application, setting their own legal disclosure, redirecting recipients to their own landing pages upon document action completion, enabling and disabling integrations, setting document and template accessibility across users with customised roles and permission profiles, creating new portals to segments users and document data, setting envelope defaults across a portal, configuring a common email to deliver documents from, and setting up domain mapping to access the app from (with domain ownership via DKIM/SPF verification and DMARC alignment). Additionally, Zoho Sign's extensive API and SDKs enable embedding and white labelling across services.
Scaling
- Independence of resources
- Zoho Sign infrastructure scales horizontally and vertically to meets increasing demands by adding more servers or resources. Load balancing techniques are in place to evenly distribute incoming requests across multiple servers. Stability in performance is achieved through continous monitoring of real time metrics such as response times, server load, and error rates. For flexible fault tolerance, redundant components and failover mechanisms are used to ensure high availability. In the event of a failure or outage, redundant systems seamlessly take over, minimising downtime and ensuring uninterrupted service for our users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Zoho Sign offers organisation and document activity report, credit consumption report. The organisation activity history can be viewed in bar graph and can be exported in CSV format. You can view the report with the document type or envelope status for a specific period. Along with this, you can also view and export your API usage.
- Reporting types
-
- API access
- Real-time dashboards
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Users can export their account activity report, document history report, documents with their completion certificate.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- ZIP
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- .DOC
- .DOCX
- .JPG
- .XLS
- .PNG
- .XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Network traffic is encrypted when it traverses over the public network and when replicating to the DR data center. Traffic inside DC is not completely encrypted, The complete Datacenter stack is under our control. We use firewalls to prevent our network from unauthorized access. Our systems are segmented into separate networks to protect sensitive data from unauthorized access.
Availability and resilience
- Guaranteed availability
- Our monthly service uptime is 99.9%. The live service availability status can be seen online. Upon customer request, Zoho will, as per the terms and conditions of its Service level agreement, provide service credits. A copy of Zoho SLA can be shared upon request.
- Approach to resilience
- Application data is stored on resilient storage that is replicated across data centres. Data in the primary DC is replicated in the secondary in near real time. In case of failure of the primary DC, secondary DC takes over and the operations are carried on smoothly with minimal or no loss of time. Both the centers are equipped with multiple ISPs. We have power back-up, temperature control systems and fire-prevention systems as physical measures to ensure business continuity. These measures help us achieve resilience. In addition to the redundancy of data, we have a business continuity plan for our major operations such as support and infrastructure management.
- Outage reporting
-
Planned Outages & Maintenance:
The planned outages would be announced/informed to the customers through several channels, blog post in community forum, business emails, banners in respective services.
Generally, annual maintenance activities would be planned during non-business hours to avoid impact to the services.
Unplanned Outages:
Major unplanned outages will be posted in social media forums & also will be informed to customers through emails. Customers can always refer to the following link on the health status of each service & update on outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
We employ technical access controls and internal policies to prohibit employees from arbitrarily accessing user data. We adhere to the principles of least privilege and role-based permissions to minimize the risk of data exposure.
Access to production environments is maintained by a central directory and authenticated using a combination of strong passwords, two-factor authentication, and passphrase-protected SSH keys. Furthermore, we facilitate such access through a separate network with stricter rules and hardened devices. Additionally, we log all the operations and audit them periodically. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI (British Standards Institution)
- ISO/IEC 27001 accreditation date
- 22/08/2022
- What the ISO/IEC 27001 doesn’t cover
- Zoho has earned ISO/IEC 27001:2013 certification for Applications, Systems, People, Technology, and Processes
- ISO 28000:2007 certification
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- 28/06/2021
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- Not Applicable
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
-
- ISO/IEC 27701
- ESQUEMA NACIONAL DE SEGURIDAD (ENS)
- FDA's 21 CFR Part 11
- Eudralex GMP Annexure 11
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Zoho shall maintain an information security program in accordance with the international standard ISO 27001, which includes technical and organisational security measures, physical measures, as well as policies and procedures to protect customer data processed by Zoho against accidental loss, destruction, or alteration, unauthorised disclosure or access, or unlawful destruction. Zoho maintains documented information security and data privacy policies and requirements, and periodically communicates them to employees responsible for various controls. The policies are reviewed annually to keep them up-to-date. This policy is verified during our third-party audits such as ISO and SOC.
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
- We have Change Management procedures in place that include, but are not limited to, all changes to the Organisation, Applications, Systems, People, Technology, and Processes, as well as information processing facilities that affect information security/privacy. For every change, the security impact is analyzed. We maintain audit logs as evidence for all changes. Fall-back procedures, including procedures and responsibilities for aborting and recovering from unsuccessful changes and unforeseen events, are documented and communicated. Zoho shall notify the customer of any changes that may affect the customer adversely.
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
-
We have a dedicated vulnerability management process that actively scans for security threats using a combination of certified third-party scanning tools and in-house tools, along with automated and manual penetration testing efforts. Our security team actively reviews inbound security reports and monitors public mailing lists, blog posts, and wikis to spot security incidents that affect the company’s infrastructure.
Once we identify a vulnerability requiring remediation, it is logged, prioritised according to severity, and assigned to an owner. We identify the associated risks and track the vulnerability until it is closed by either patching the vulnerable systems or applying relevant controls. - Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
- We monitor and analyse information gathered from services, internal traffic in our network, and usage of devices and terminals. We record this information in the form of event logs, audit logs, fault logs, administrator logs, and operator logs. These logs are automatically monitored and analysed to a reasonable extent to help us identify anomalies, such as unusual activity in employees’ accounts or attempts to access customer data. We store these logs on a secure server isolated from full system access to manage access control centrally and ensure availability.
- Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
-
Our incident management team notifies you of the relevant incidents and actions needed. We track and close the incidents with corrective actions. Whenever applicable, we will provide you with necessary evidence in the form of application and audit logs regarding incidents. Furthermore, we implement controls to prevent the recurrence of similar situations.
We respond to the security or privacy incidents you report to us through incidents@zohocorp.com with high priority. For general incidents, we will notify users through our blogs, forums, and social media. For incidents specific to an individual user or organization, we will notify the concerned party through email.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
The energy supply for the Zoho UK’s workspace at Bletchley is derived from renewable sources, accounting for 21% of total power consumption. LED retrofits have been implemented to enhance energy efficiency throughout the building.
Designed with a focus on energy efficiency, data centres that support Zoho UK are powered by renewable energy. Further, these data centres are progressing towards integrating with a solar grid to reduce environmental impacts.
All purchased energy for the data centres is sourced from green energy providers. This enables us to minimise the carbon footprint associated with our operations.
The United Kingdom has committed to achieving carbon neutrality by 2050. Supporting this pledge, we have taken steps to monitor greenhouse gas (GHG) emissions from our operations and implement measures to mitigate them. We account for Scope 2 and Scope 3 emissions and exclude Scope 1 emissions as our work does not involve fuel combustion within operational boundaries.
We've switched completely to electric vehicles for movement within the campus.Covid-19 recovery
During the COVD-19 pandemic, Zoho worked to minimize the impact of COVID on our customers, other business and our local community.
At the start of the pandemic, Zoho created and distributed a Secure Remote Access Toolkit to help organizations quickly adapt to and work securely during the pandemic. This toolkit was made free for the first 100 days.
To assist organizations impacted by the pandemic, Zoho offered free licenses of flagship products, and offered discounts and waivers on licenses on a case-by-case basis.
While most of our employees worked from home, we kept the kitchen at our Chennai headquarters running with a skeletal staff to provide food to underprivileged people in the local area, many of whom were impacted due to a loss of employment during the lockdown.
We converted one of our office buildings into a temporary COVID-19 ward to accommodate citizens who were required to quarantine.
We ran Covid vaccination camps to our employees, their dependents and the support staff who worked in Zoho.Tackling economic inequality
Zoho has always aimed to tackle economic inequality and give back to the community. This is reflected in the following:
Coined by our CEO, transnational localism is the philosophy that underpins our staffing and office location plans. Instead of focusing on crowded urban centres, we've been opening spoke offices in smaller towns and villages. The goal is to improve local infrastructure, boost the economy of these smaller towns and villages, and provide more employment opportunity.
As part of our philosophy of transnational localism, we believe in hiring locally for each spoke office. This helps promote local talent and bring high-paying jobs back to the villages and towns where we are based.Equal opportunity
As part of our efforts to tackle inequality, Zoho Corporation Limited have made efforts to provide equal opportunities and tackle workforce inequality.
All roles at Zoho Corporation are open to all people irrespective of gender, sex, race, ability, or religion. We hire solely based on skill and have a diverse team.
We eschew discrimination on any grounds, including age, colour, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, and other unique characteristics that define our associates. Instead, we espouse, fairness, striving to ensure that a merit-based approach allows wage parity among associates with comparable experiences and responsibilities, irrespective of their gender.
Our campus has been designed to be accessible to all, including differently-abled colleagues. The layout design includes ramps and lifts in every building, allowing ease of mobility and access to all.
Apart from the usual shuttle facilities, special cab service covering a certain distance is given for women during their third trimester.Wellbeing
Zoho Corporation Limited adheres to industry standards in remuneration, ensuring that compensation is equitable across genders. Recognising the diverse needs of our people, we provide essential support such as parental leave, aligning with our efforts to build an organisation that values and cares for every individual.
We have trained medical practitioners and a dedicated medical clinic available on all days of the week. Employees can freely avail their services.
The Hazard Identification & Risk Assessment (HIRA) Framework is followed rigorously at the premises.
We provide in-house counselling to our employees for free via our team of trained and qualified therapists.
We organize free medical check-ups for our employees on an annual basis.
We organize regular blood donation camps in association with various blood banks.
We have open house sessions conducted by the CEO periodically where employees can raise any concerns.
Day Care facilities provided for employees kids
The compliance monitoring framework involves ongoing reviews and enhancements of occupational health programmes, guided by feedback, data analysis, and emerging best practices.
Pricing
- Price
- £10 to £22 a user a month
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Zoho Sign has a free plan that offers only the core functions such as signing and sending documents out for signatures, sending reminders, tracking document status in real-time, and accessing audit trails. However, the plan limits usage to one user per organisation and getting only 5 envelopes signed per month.
- Link to free trial
- https://www.zoho.eu/sign/signup.html