Self-Hosting Docuseal on a VPS: Building a Secure, Open-Source Digital Signature Platform to Replace DocuSign
Introduction: The Cost and Compliance Challenge of Digital Signatures
In today's digital-first business environment, the ability to sign and execute contracts remotely is no longer a luxury—it is a operational necessity. For years, platforms like DocuSign, HelloSign, and Adobe Sign have dominated the market. However, as organizations scale, they inevitably run into two major friction points: exponentially increasing subscription costs and growing data privacy concerns.
Per-user or per-envelope pricing models can quickly turn digital signatures into a massive operational expense. More importantly, relying on third-party SaaS providers means trusting them with highly sensitive business contracts, financial agreements, and proprietary intellectual property. For industries bound by strict compliance frameworks (such as GDPR, HIPAA, or local data localization laws), letting corporate agreements sit on external cloud servers introduces significant regulatory risks.
Enter Docuseal, a powerful, open-source alternative that allows businesses to self-host their own digital signature infrastructure. By deploying Docuseal on a Virtual Private Server (VPS), you can completely eliminate per-document fees, enforce total data sovereignty, and maintain absolute control over your signing workflows. This guide provides a step-by-step blueprint for deploying, configuring, and securing Docuseal on a VPS for production use.
Why Docuseal is the Premier Open-Source Alternative to DocuSign
Docuseal is designed from the ground up to match the user experience of enterprise SaaS platforms while offering the flexibility of open-source software. Key advantages of choosing Docuseal for your corporate infrastructure include:
- Zero Per-Envelope Fees: Send and sign an unlimited number of documents without worrying about tier-based overage charges or artificial limits.
- Absolute Data Sovereignty: Your documents, audit logs, and signer cryptographic data remain entirely within your controlled environment. No external third party ever has access to your business intelligence.
- Advanced PDF Field Management: Intuitively place signature blocks, text fields, checkboxes, dates, and initials using a streamlined drag-and-drop builder.
- Automated Document Workflows: Build reusable templates, set explicit signing orders for multiple stakeholders, and configure automated email reminders to keep deals moving forward.
- Developer-Friendly API: Easily integrate document signing workflows into your existing internal tools, CRM systems, or customer portals via a robust REST API and webhooks.
Prerequisites for Deployment
Before initiating the installation process, ensure your infrastructure meets the following baseline requirements to guarantee optimal performance and security:
- A Dedicated VPS: A virtual private server running a modern Linux distribution (Ubuntu 22.04 LTS or newer is highly recommended). For small to medium businesses, a starter instance with 2 vCPUs, 2GB or 4GB of RAM, and SSD storage is fully sufficient.
- A Domain Name: A fully qualified domain name (FQDN), such as
sign.yourcompany.com, with its DNS 'A' record pointing directly to your VPS public IP address. - Docker and Docker Compose: The cleanest and most maintainable way to run Docuseal is via containerization. Ensure both Docker engine and the Docker Compose plugin are pre-installed on the host system.
Step-by-Step Architecture Deployment via Docker Compose
Deploying Docuseal via Docker Compose ensures isolated environment management and allows you to easily couple the application with an automated reverse proxy like Nginx or Caddy to handle SSL certificates. Follow these operational steps to provision your platform.
Step 1: System Update and Directory Structure Setup
Connect to your VPS via SSH and verify that your system repositories are fully updated. Then, create a dedicated project directory to hold your configuration files:
sudo apt update && sudo apt upgrade -y
mkdir -p ~/docuseal-platform && cd ~/docuseal-platform
Step 2: Configuring the Docker Compose File
Create a production-ready docker-compose.yml file. In this setup, we will configure Docuseal alongside a lightweight PostgreSQL database container to store application records reliably, and a Traefik or Nginx proxy container to orchestrate secure traffic. For maximum simplicity and automated security, we will use an integrated environment block:
Security Note: Always ensure your database passwords and application secret keys are stored securely using environment variables or dedicated secret managers rather than hardcoding them into production files.
Create the file using your preferred text editor (such as Nano or Vim):
nano docker-compose.yml
Populate the file with the following standard, highly efficient service stack topology:
version: '3.8'
services:
docuseal:
image: docuseal/docuseal:latest
container_name: docuseal_app
environment:
- DATABASE_URL=postgresql://docuseal_user:SecureDBPassword123@db:5432/docuseal_prod
- PORT=3000
- SECRET_KEY_BASE=your_long_random_generated_hex_secret_here
ports:
- "127.0.0.1:3000:3000"
restart: always
depends_on:
- db
volumes:
- docuseal_data:/data
db:
image: postgres:15-alpine
container_name: docuseal_db
environment:
- POSTGRES_USER=docuseal_user
- POSTGRES_PASSWORD=SecureDBPassword123
- POSTGRES_DB=docuseal_prod
volumes:
- postgres_data:/var/lib/postgresql/data
restart: always
volumes:
docuseal_data:
postgres_data:
Step 3: Launching the Application Services
With the composition file saved, initialize and download the container images in detached background mode by executing:
docker compose up -d
Verify that both containers are running optimally by checking their health logs via docker compose ps. The application server will now be listening locally on port 3000.
Securing the Deployment: Reverse Proxy and Let's Encrypt SSL
Exposing a signing platform directly over unencrypted HTTP protocol is an unacceptable risk for business operations. All data transit—especially legally binding contracts—must be encrypted via TLS/SSL. We will configure Nginx as a reverse proxy to manage traffic routing and deploy Let's Encrypt certificates automatically.
Step 1: Install Nginx and Certbot
Run the following command to download Nginx along with the Certbot utility for automated Let's Encrypt certificate acquisition:
sudo apt install nginx certbot python3-certbot-nginx -y
Step 2: Configure the Nginx Server Block
Create a dedicated configuration block for your new domain profile:
sudo nano /etc/nginx/sites-available/docuseal.conf
Paste the configuration below, replacing sign.yourcompany.com with your actual business subdomain:
server {
listen 80;
server_name sign.yourcompany.com;
location / {
proxy_pass [http://127.0.0.1:3000](http://127.0.0.1:3000);
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# WebSockets support for real-time updates
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}
Enable the site and restart the Nginx web routing layer:
sudo ln -s /etc/nginx/sites-available/docuseal.conf /etc/nginx/sites-enabled/
sudo systemctl restart nginx
Step 3: Generate the SSL Certificate
Execute Certbot to request an enterprise-grade SSL certificate and let it automatically modify the Nginx traffic rules to mandate a strict HTTPS connection redirect:
sudo certbot --nginx -d sign.yourcompany.com
Follow the onscreen prompts to input your admin email and agree to the terms of service. Once complete, your Docuseal installation is fully protected with modern TLS encryption.
Essential Post-Installation Configuration and Best Practices
Navigate to [https://sign.yourcompany.com](https://sign.yourcompany.com) in your browser to complete the initial setup wizard. To ready the system for professional business workflows, optimize these three core areas:
1. SMTP Email Server Integration
Docuseal relies heavily on email systems to send signing requests to third parties and return completed copies to all stakeholders. Navigate immediately to the Settings > SMTP Configuration panel and link your corporate mail provider (such as Amazon SES, SendGrid, or Google Workspace). Always test verification flows to ensure invitations do not arrive in clients' spam folders.
2. Advanced Security Hardening
To maximize the legal validity and security compliance of your documents, consider implementing the following policies:
- Enforce Strong MFA: Require Multi-Factor Authentication for all internal administrators and staff members who build templates or view sensitive completed files.
- Automated Database Backups: Schedule automated nightly cron jobs on your VPS to compress and back up your Postgres data volumes to an off-site, secure cloud bucket or cold-storage network.
- Strict Firewalling: Use Linux
ufw(Uncomplicated Firewall) to block all unnecessary external ports, leaving only ports 80 and 443 open to the public internet.
3. White-Label Branding Customization
One of Docuseal's most compelling business features is its native support for complete white-label branding. Upload your company's high-resolution logo, specify corporate brand colors for the user interface buttons, and update email templates with personalized headers. Your external partners and clients will experience a cohesive, professional ecosystem branded entirely to your firm, fostering trust during crucial contract signing moments.
Conclusion: Long-Term Independence and Strategic Value
By migrating your digital signing infrastructure from expensive cloud aggregators to a self-hosted Docuseal platform on a secure VPS, you achieve two monumental milestones for your enterprise: unprecedented cost efficiency and uncompromising security assurance. Your contracts stay within your borders, your data scales organically with your computing limits, and your overhead becomes highly predictable. Taking control of your technical stack today guarantees your business operations remain secure, compliant, and ready for future growth.
