Back to articles
Technology Insight

Self-Hosting DocuSeal on a VPS: Building a Secure, In-House Electronic Signature System

May 30, 2026

Introduction to Self-Hosted Document Signing

In the modern corporate ecosystem, digital transformation is no longer a luxury—it is a baseline requirement. Among the various pillars of digital operations, electronic signatures (e-signatures) have become indispensable for legal compliance, procurement, human resources, and sales velocity. While third-party Software-as-a-Service (SaaS) platforms like DocuSign or Adobe Sign are widely adopted, they introduce significant long-term operational challenges. These include recurring per-user or per-document fees, unpredictable pricing escalations, and complex data residency concerns.

For enterprises and growing businesses committed to data sovereignty and cost efficiency, self-hosting is the ultimate strategic pivot. DocuSeal emerged as a powerful, open-source alternative that allows organizations to host their own secure e-signature platform. By deploying DocuSeal on a Virtual Private Server (VPS), you retain absolute control over your sensitive PDF contracts, client data, and audit trails, all while eliminating external subscription costs. This guide delivers an enterprise-grade blueprint for deploying, configuring, and securing DocuSeal on your own infrastructure.

Strategic Advantages of Deploying DocuSeal on a VPS

Transitioning from a public cloud SaaS model to a private self-hosted architecture yields several critical advantages for corporate entities:

  • Absolute Data Control: Your legal contracts, financial agreements, and employee records remain strictly on your server. This eliminates the risk of third-party data breaches and simplifies compliance with local data privacy frameworks.
  • Substantial Cost Efficiency: Traditional e-signature providers scale costs based on transaction volume (envelopes) or seat count. A self-hosted VPS model incurs a predictable, fixed infrastructure cost, regardless of how many thousands of documents you sign.
  • Customization and API Integration: DocuSeal provides robust developer APIs and webhooks. Running it on your own server allows seamless, deep integration into existing enterprise resource planning (ERP) systems, customer relationship management (CRM) tools, and automated legal pipelines.

Pre-deployment Requirements and Architecture Planning

Before initiating the technical deployment, ensure your infrastructure meets the standard baseline requirements for an enterprise-grade production environment:

  1. Virtual Private Server (VPS): A minimum configuration of 2 vCPUs, 2GB or 4GB of RAM, and 40GB of SSD storage. Linux distributions such as Ubuntu 22.04 LTS or Ubuntu 24.04 LTS are highly recommended for stability and broad community support.
  2. Domain and DNS Control: A fully qualified domain name (FQDN), such as sign.yourcompany.com, with an A Record pointing directly to your VPS public IP address.
  3. Network and Security: Open standard ports for web traffic: Port 80 (HTTP) and Port 443 (HTTPS), along with SSH (Port 22) secured via public key authentication.

Step-by-Step Installation Guide via Docker Compose

Utilizing Docker and Docker Compose ensures a clean, isolated, and easily maintainable deployment. This method containerizes the application logic and the database, preventing software dependency conflicts on your host OS.

Step 1: System Update and Docker Installation

Connect to your VPS via SSH and execute the following commands to update core repositories and install the Docker engine ecosystem:

sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose-plugin -y
sudo systemctl enable --now docker

Step 2: Structuring the Project Directory

Create a dedicated directory to manage your DocuSeal deployment artifacts, environment configurations, and persistent volume data:

mkdir -p ~/docuseal && cd ~/docuseal

Step 3: Creating the Docker Compose Blueprint

Create a new configuration file named docker-compose.yml using a text editor like Nano:

nano docker-compose.yml

Populate the file with the optimized enterprise configuration block below, which leverages PostgreSQL as the robust database backend instead of default lightweight databases:

version: '3.8'

services:
  db:
    image: postgres:15-alpine
    container_name: docuseal_db
    restart: always
    environment:
      POSTGRES_USER: docuseal_user
      POSTGRES_PASSWORD: SecureDatabasePassword123!
      POSTGRES_DB: docuseal_production
    volumes:
      - db_data:/var/lib/postgresql/data

  app:
    image: docuseal/docuseal:latest
    container_name: docuseal_app
    restart: always
    ports:
      - "3000:3000"
    depends_on:
      - db
    environment:
      - DATABASE_URL=postgresql://docuseal_user:SecureDatabasePassword123!@db:5432/docuseal_production
      - SECRET_KEY_BASE=GenerateALongRandomHexadecimalStringForSecurity
    volumes:
      - app_data:/data

volumes:
  db_data:
  app_data:
Security Warning: Always replace the placeholder values for POSTGRES_PASSWORD and SECRET_KEY_BASE with unique, cryptographically secure keys before running this container cluster in production.

Step 4: Launching the Application Ecosystem

With the orchestration file properly configured, initialize the multi-container environment in detached background mode:

sudo docker compose up -d

Verify that both containers are running optimally by reviewing the active process list:

sudo docker compose ps

Configuring Nginx Reverse Proxy and Let's Encrypt SSL

Exposing raw container ports directly to the internet is not recommended. To establish professional, encrypted HTTPS traffic, we will use Nginx as a reverse proxy coupled with automated Let's Encrypt SSL certificates.

Step 1: Install Nginx

Install the Nginx web server package on the host operating system:

sudo apt install nginx -y

Step 2: Configure the Virtual Host

Create an Nginx server block specifically tailored for your DocuSeal instance:

sudo nano /etc/nginx/sites-available/docuseal

Insert the following configuration layout, substituting your actual domain name:

server {
    listen 80;
    server_name sign.yourcompany.com;

    location / {
        proxy_pass [http://127.0.0.1:3000](http://127.0.0.1:3000);
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded-for;
        proxy_set_header X-Forwarded-Proto $scheme;
    
        # Extended timeouts for large PDF processing
        proxy_connect_timeout 300s;
        proxy_send_timeout 300s;
        proxy_read_timeout 300s;
        client_max_body_size 50M;
    }
}

Enable the site configuration and restart Nginx to apply changes:

sudo ln -s /etc/nginx/sites-available/docuseal /etc/nginx/sites-enabled/
sudo systemctl restart nginx

Step 3: Secure the Traffic via Certbot

Deploy Certbot to generate and automatically renew trusted SSL certificates:

sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d sign.yourcompany.com

Follow the interactive prompts to complete the configuration. Certbot will automatically inject the required SSL settings, instantly redirecting all legacy HTTP traffic to highly secure HTTPS.

Enterprise Post-Installation Configuration

With network routing secured, navigate to [https://sign.yourcompany.com](https://sign.yourcompany.com) via a web browser to complete the initial setup wizard.

1. Administrative Account Setup

The first user to access the interface will establish the master administrative profile. Choose a highly complex password and configure multi-factor authentication (MFA) immediately within the user profile settings dashboard.

2. SMTP Gateway Configuration

DocuSeal relies heavily on transactional emails to send signature requests and completion notifications to external clients. Navigate to the Settings > SMTP menu and configure your corporate mail transport layer (e.g., SendGrid, AWS SES, or internal corporate mail exchanges). Test the transport layer to ensure signature invitations successfully bypass modern spam filters.

3. Branding and Customization

To preserve your company's visual identity, upload high-resolution corporate logos, adjust the primary accent colors to match corporate guidelines, and customize the outbound email signatures and templates. This builds trust with external signatories who interact with your self-hosted portal.

Conclusion and Ongoing Infrastructure Maintenance

Deploying DocuSeal on a private VPS successfully bridges the gap between digital operational efficiency and rigid data security policies. Your enterprise now possesses a scalable, cost-effective, and fully owned electronic signature infrastructure capable of handling high-volume contract workflows without external dependencies.

To maintain long-term stability, ensure you schedule automated nightly backups of your Docker volumes (specifically the application data and PostgreSQL schemas). Regularly execute docker compose pull to retrieve security patches and feature updates issued by the active DocuSeal development community. By doing so, your digital signature platform will remain safe, compliant, and highly performant for years to come.

Self-Hosting DocuSeal on a VPS: Building a Secure, In-House Electronic Signature System | DPTCloud