Back to articles
Technology Insight

Self-Hosting Docuseal on a VPS: Building a Secure, Open-Source Digital Signature Platform to Replace DocuSign

June 1, 2026

Introduction: The Cost and Compliance Challenge of Digital Signatures

In today's digital-first business environment, the ability to sign and execute contracts remotely is no longer a luxury—it is a operational necessity. For years, platforms like DocuSign, HelloSign, and Adobe Sign have dominated the market. However, as organizations scale, they inevitably run into two major friction points: exponentially increasing subscription costs and growing data privacy concerns.

Per-user or per-envelope pricing models can quickly turn digital signatures into a massive operational expense. More importantly, relying on third-party SaaS providers means trusting them with highly sensitive business contracts, financial agreements, and proprietary intellectual property. For industries bound by strict compliance frameworks (such as GDPR, HIPAA, or local data localization laws), letting corporate agreements sit on external cloud servers introduces significant regulatory risks.

Enter Docuseal, a powerful, open-source alternative that allows businesses to self-host their own digital signature infrastructure. By deploying Docuseal on a Virtual Private Server (VPS), you can completely eliminate per-document fees, enforce total data sovereignty, and maintain absolute control over your signing workflows. This guide provides a step-by-step blueprint for deploying, configuring, and securing Docuseal on a VPS for production use.

Why Docuseal is the Premier Open-Source Alternative to DocuSign

Docuseal is designed from the ground up to match the user experience of enterprise SaaS platforms while offering the flexibility of open-source software. Key advantages of choosing Docuseal for your corporate infrastructure include:

  • Zero Per-Envelope Fees: Send and sign an unlimited number of documents without worrying about tier-based overage charges or artificial limits.
  • Absolute Data Sovereignty: Your documents, audit logs, and signer cryptographic data remain entirely within your controlled environment. No external third party ever has access to your business intelligence.
  • Advanced PDF Field Management: Intuitively place signature blocks, text fields, checkboxes, dates, and initials using a streamlined drag-and-drop builder.
  • Automated Document Workflows: Build reusable templates, set explicit signing orders for multiple stakeholders, and configure automated email reminders to keep deals moving forward.
  • Developer-Friendly API: Easily integrate document signing workflows into your existing internal tools, CRM systems, or customer portals via a robust REST API and webhooks.

Prerequisites for Deployment

Before initiating the installation process, ensure your infrastructure meets the following baseline requirements to guarantee optimal performance and security:

  1. A Dedicated VPS: A virtual private server running a modern Linux distribution (Ubuntu 22.04 LTS or newer is highly recommended). For small to medium businesses, a starter instance with 2 vCPUs, 2GB or 4GB of RAM, and SSD storage is fully sufficient.
  2. A Domain Name: A fully qualified domain name (FQDN), such as sign.yourcompany.com, with its DNS 'A' record pointing directly to your VPS public IP address.
  3. Docker and Docker Compose: The cleanest and most maintainable way to run Docuseal is via containerization. Ensure both Docker engine and the Docker Compose plugin are pre-installed on the host system.

Step-by-Step Architecture Deployment via Docker Compose

Deploying Docuseal via Docker Compose ensures isolated environment management and allows you to easily couple the application with an automated reverse proxy like Nginx or Caddy to handle SSL certificates. Follow these operational steps to provision your platform.

Step 1: System Update and Directory Structure Setup

Connect to your VPS via SSH and verify that your system repositories are fully updated. Then, create a dedicated project directory to hold your configuration files:

sudo apt update && sudo apt upgrade -y
mkdir -p ~/docuseal-platform && cd ~/docuseal-platform

Step 2: Configuring the Docker Compose File

Create a production-ready docker-compose.yml file. In this setup, we will configure Docuseal alongside a lightweight PostgreSQL database container to store application records reliably, and a Traefik or Nginx proxy container to orchestrate secure traffic. For maximum simplicity and automated security, we will use an integrated environment block:

Security Note: Always ensure your database passwords and application secret keys are stored securely using environment variables or dedicated secret managers rather than hardcoding them into production files.

Create the file using your preferred text editor (such as Nano or Vim):

nano docker-compose.yml

Populate the file with the following standard, highly efficient service stack topology:

version: '3.8'

services:
  docuseal:
    image: docuseal/docuseal:latest
    container_name: docuseal_app
    environment:
      - DATABASE_URL=postgresql://docuseal_user:SecureDBPassword123@db:5432/docuseal_prod
      - PORT=3000
      - SECRET_KEY_BASE=your_long_random_generated_hex_secret_here
    ports:
      - "127.0.0.1:3000:3000"
    restart: always
    depends_on:
      - db
    volumes:
      - docuseal_data:/data

  db:
    image: postgres:15-alpine
    container_name: docuseal_db
    environment:
      - POSTGRES_USER=docuseal_user
      - POSTGRES_PASSWORD=SecureDBPassword123
      - POSTGRES_DB=docuseal_prod
    volumes:
      - postgres_data:/var/lib/postgresql/data
    restart: always

volumes:
  docuseal_data:
  postgres_data:

Step 3: Launching the Application Services

With the composition file saved, initialize and download the container images in detached background mode by executing:

docker compose up -d

Verify that both containers are running optimally by checking their health logs via docker compose ps. The application server will now be listening locally on port 3000.

Securing the Deployment: Reverse Proxy and Let's Encrypt SSL

Exposing a signing platform directly over unencrypted HTTP protocol is an unacceptable risk for business operations. All data transit—especially legally binding contracts—must be encrypted via TLS/SSL. We will configure Nginx as a reverse proxy to manage traffic routing and deploy Let's Encrypt certificates automatically.

Step 1: Install Nginx and Certbot

Run the following command to download Nginx along with the Certbot utility for automated Let's Encrypt certificate acquisition:

sudo apt install nginx certbot python3-certbot-nginx -y

Step 2: Configure the Nginx Server Block

Create a dedicated configuration block for your new domain profile:

sudo nano /etc/nginx/sites-available/docuseal.conf

Paste the configuration below, replacing sign.yourcompany.com with your actual business subdomain:

server {
    listen 80;
    server_name sign.yourcompany.com;

    location / {
        proxy_pass [http://127.0.0.1:3000](http://127.0.0.1:3000);
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    
        # WebSockets support for real-time updates
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

Enable the site and restart the Nginx web routing layer:

sudo ln -s /etc/nginx/sites-available/docuseal.conf /etc/nginx/sites-enabled/
sudo systemctl restart nginx

Step 3: Generate the SSL Certificate

Execute Certbot to request an enterprise-grade SSL certificate and let it automatically modify the Nginx traffic rules to mandate a strict HTTPS connection redirect:

sudo certbot --nginx -d sign.yourcompany.com

Follow the onscreen prompts to input your admin email and agree to the terms of service. Once complete, your Docuseal installation is fully protected with modern TLS encryption.

Essential Post-Installation Configuration and Best Practices

Navigate to [https://sign.yourcompany.com](https://sign.yourcompany.com) in your browser to complete the initial setup wizard. To ready the system for professional business workflows, optimize these three core areas:

1. SMTP Email Server Integration

Docuseal relies heavily on email systems to send signing requests to third parties and return completed copies to all stakeholders. Navigate immediately to the Settings > SMTP Configuration panel and link your corporate mail provider (such as Amazon SES, SendGrid, or Google Workspace). Always test verification flows to ensure invitations do not arrive in clients' spam folders.

2. Advanced Security Hardening

To maximize the legal validity and security compliance of your documents, consider implementing the following policies:

  • Enforce Strong MFA: Require Multi-Factor Authentication for all internal administrators and staff members who build templates or view sensitive completed files.
  • Automated Database Backups: Schedule automated nightly cron jobs on your VPS to compress and back up your Postgres data volumes to an off-site, secure cloud bucket or cold-storage network.
  • Strict Firewalling: Use Linux ufw (Uncomplicated Firewall) to block all unnecessary external ports, leaving only ports 80 and 443 open to the public internet.

3. White-Label Branding Customization

One of Docuseal's most compelling business features is its native support for complete white-label branding. Upload your company's high-resolution logo, specify corporate brand colors for the user interface buttons, and update email templates with personalized headers. Your external partners and clients will experience a cohesive, professional ecosystem branded entirely to your firm, fostering trust during crucial contract signing moments.

Conclusion: Long-Term Independence and Strategic Value

By migrating your digital signing infrastructure from expensive cloud aggregators to a self-hosted Docuseal platform on a secure VPS, you achieve two monumental milestones for your enterprise: unprecedented cost efficiency and uncompromising security assurance. Your contracts stay within your borders, your data scales organically with your computing limits, and your overhead becomes highly predictable. Taking control of your technical stack today guarantees your business operations remain secure, compliant, and ready for future growth.

Self-Hosting Docuseal on a VPS: Building a Secure, Open-Source Digital Signature Platform to Replace DocuSign | DPTCloud