Back to articles
Technology Insight

Self-Hosting Docuseal on a VPS: Building a Secure Digital Signature Platform to Replace DocuSign

June 1, 2026

Introduction: The Rising Cost of Digital Signatures

In today's digital-first business environment, the ability to sign agreements, contracts, and onboarding documents remotely is no longer a luxury—it is an operational necessity. For years, platforms like DocuSign and Adobe Sign have dominated the market. However, as organizations scale, the licensing costs of these proprietary, per-user or per-document subscription models can escalate exponentially.

Beyond the financial burden, data sovereignty and compliance have become paramount. Entrusting sensitive corporate legal documents to third-party cloud providers introduces security risks and potential compliance headaches with strict regulations like GDPR or HIPAA. This has led forward-thinking enterprises to look for a self-hosted alternative. Enter Docuseal: an open-source, powerful, and secure digital signature platform that you can deploy entirely on your own virtual private server (VPS).


What is Docuseal?

Docuseal is a robust, mobile-optimized, open-source digital signature platform designed to create, fill, and sign PDF documents digitally. It serves as a seamless, feature-rich alternative to commercial e-signature platforms, providing automated email notifications, user management, and seamless API integrations. By self-hosting Docuseal, businesses gain absolute ownership over their data, reduce operational costs to a predictable flat VPS rate, and maintain stringent security controls.

Key Benefits of Self-Hosting Docuseal

  • Cost Efficiency: Eliminate per-envelope or per-user pricing. You only pay for your underlying VPS infrastructure.
  • Data Sovereignty: Your documents, signatures, and audit trails remain on your server, ensuring full compliance with local data protection laws.
  • Customization and Integration: Easily integrate Docuseal into your existing CRM, ERP, or custom software via its developer-friendly REST API and webhooks.
  • User Experience: Deliver a sleek, responsive signing interface for both desktop and mobile users without external branding constraints.

Prerequisites for VPS Deployment

Before initiating the installation process, ensure your infrastructure meets the following baseline requirements to guarantee stability and security:

  • VPS Hosting: A virtual private server running a stable Linux distribution, preferably Ubuntu 22.04 LTS or Ubuntu 24.04 LTS.
  • Hardware Specifications: A minimum of 1 vCPU, 2 GB RAM, and 20 GB of SSD storage (scale storage based on your expected document volume).
  • Domain Name: A registered domain or subdomain (e.g., sign.yourcompany.com) pointed to your VPS IP address via an A Record.
  • Docker Installed: Docker and Docker Compose configured on the host machine for streamlined containerization.

Step-by-Step Deployment Guide

Step 1: System Update and Docker Installation

First, securely log into your VPS via SSH and update the system packages to their latest versions:

sudo apt update && sudo apt upgrade -y

Next, install Docker and Docker Compose if they are not already present on your system:

sudo apt install docker.io docker-compose -y
sudo systemctl enable --now docker

Step 2: Configuring the Docker Compose Environment

Create a dedicated directory for your Docuseal deployment to keep files organized:

mkdir ~/docuseal && cd ~/docuseal

Create a docker-compose.yml file using your preferred text editor:

nano docker-compose.yml

Paste the following optimized configuration into the file. This setup configures the Docuseal web application alongside a persistent PostgreSQL database for enterprise-grade data management:

version: '3.8'

services:
  db:
    image: postgres:15-alpine
    environment:
      POSTGRES_USER: docuseal_user
      POSTGRES_PASSWORD: YourSecurePasswordHere
      POSTGRES_DB: docuseal_production
    volumes:
      - postgres_data:/var/lib/postgresql/data
    restart: always

  web:
    image: docuseal/docuseal:latest
    environment:
      DATABASE_URL: postgres://docuseal_user:YourSecurePasswordHere@db:5432/docuseal_production
      PORT: 3000
      SECRET_KEY_BASE: GenerateALongRandomHexKeyHere
    ports:
      - "127.0.0.1:3000:3000"
    depends_on:
      - db
    restart: always

volumes:
  postgres_data:

Note: Replace "YourSecurePasswordHere" and "GenerateALongRandomHexKeyHere" with unique, highly complex alphanumeric strings to secure your deployment. Save and close the file.

Step 3: Launching Docuseal Containers

Execute the following command to pull the required images and start the services in detached mode:

docker-compose up -d

Verify that both containers are running smoothly by checking their statuses:

docker-compose ps

Securing Your Platform with Nginx and Let's Encrypt SSL

Exposing an e-signature platform over an unencrypted HTTP connection is a severe security risk. To safeguard sensitive legal documents, we must configure Nginx as a reverse proxy and implement a free Let's Encrypt SSL certificate.

Step 1: Install Nginx and Certbot

sudo apt install nginx certbot python3-certbot-nginx -y

Step 2: Configure the Nginx Server Block

Create a new configuration file for your Docuseal domain:

sudo nano /etc/nginx/sites-available/docuseal

Insert the following configuration, ensuring you replace sign.yourcompany.com with your actual domain:

server {
    listen 80;
    server_name sign.yourcompany.com;

    location / {
        proxy_pass [http://127.0.0.1:3000](http://127.0.0.1:3000);
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Enable the configuration by creating a symlink and restarting Nginx:

sudo ln -s /etc/nginx/sites-available/docuseal /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl restart nginx

Step 3: Provision the SSL Certificate

Run Certbot to automatically obtain and configure an SSL certificate from Let's Encrypt:

sudo certbot --nginx -d sign.yourcompany.com

Follow the on-screen prompts, agree to the terms of service, and allow Certbot to automatically redirect all HTTP traffic to HTTPS. Your platform is now encrypted with industry-standard TLS.


Initial Setup and Best Practices

With deployment complete, navigate to [https://sign.yourcompany.com](https://sign.yourcompany.com) in your browser. You will be greeted by the initial setup wizard. Follow these essential final steps:

  1. Create the Admin Account: Set up a strong administrator username and password. This account will manage global configurations, templates, and users.
  2. Configure SMTP Settings: To send document signing links to clients, integrate your preferred corporate email delivery service (such as SendGrid, AWS SES, or Mailgun) within the settings panel.
  3. Enable Two-Factor Authentication (2FA): Enforce 2FA for all administrative and standard internal user accounts to mitigate credential-stuffing vulnerabilities.
  4. Automate Backups: Implement a cron job on your VPS to routinely backup the PostgreSQL database volumes and store them in a secure, off-site cloud storage bucket.

Conclusion

By moving from restrictive SaaS subscriptions like DocuSign to a self-hosted Docuseal instance on a VPS, your business achieves a rare trifecta: dramatic cost savings, absolute data sovereignty, and uncompromised operational flexibility. Taking control of your digital signature infrastructure ensures that your legal workflows remain secure, scalable, and completely under your oversight for years to come.

Self-Hosting Docuseal on a VPS: Building a Secure Digital Signature Platform to Replace DocuSign | DPTCloud