| 1. Compliance (20%) | Certifications and assessments (ISO 27001, SOC 2 Type II) plus evidence mapped to the regimes that apply to you — e.g. 21 CFR Part 11, HIPAA, eIDAS QES, GDPR | Which regimes are you assessed against? Can you share audit reports and the scope of each certification? How do you support QES where required? | Generic “fully compliant” claims with no named standard, no scope, and no evidence |
|---|
| 2. Identity assurance (15%) | Range of identity methods: SMS, knowledge-based, government ID, national eID, QES-grade identity | Which methods do you support and in which countries? Is identity verification included or an add-on, and at what cost per signer? | No published identity options, or identity priced as a surprise per-transaction fee |
|---|
| 3. Evidence & audit trail (15%) | Computer-generated, time-stamped audit trail of every action; tamper-evidence; exportable evidence package | How is the audit trail generated and stored? Who can modify it? Can we export a complete evidence file and verify it independently? | No audit trail, or trail that cannot be exported or verified |
|---|
| 4. API & integration (10%) | REST API, webhooks, SDKs, maintained connectors for CRM/ERP (Salesforce, SAP, etc.) | What are the API rate limits and sandbox terms? Which connectors are maintained by the vendor rather than the community? Is API access on the standard plan? | API on a separate negotiated plan, no public documentation, no sandbox |
|---|
| 5. Data residency (10%) | Where documents and metadata are stored and processed; region pinning; sub-processor transparency | Which regions can we choose? Can data be pinned to a specific region? Who are your sub-processors and where do they process data? | Single region only, no residency options, no sub-processor list |
|---|
| 6. Support & onboarding (10%) | Support SLA and channels, onboarding program, training, time-to-value | What is the support SLA? Who runs onboarding and how long does it take? Is training included? | No published SLA, self-serve only, no onboarding path |
|---|
| 7. Pricing model (10%) | How cost scales: per-user subscription, per-envelope, API volume, enterprise custom; identity and add-on fees | What drives cost as volume grows? Which fees are separate (identity, SMS, API)? Is annual billing required? What is the renewal increase policy? | Unpublished pricing, opaque per-transaction fees, long lock-in without price protection |
|---|
| 8. Migration & exit (10%) | Export of completed documents, templates, contacts and audit data; exit terms | How do we export all completed documents and evidence? Is there a documented exit process and data-deletion timeline? | No self-serve export, data hostage risk, punitive exit terms |
|---|