# Adobe Acrobat Sign privacy rating

Adobe's electronic signature service for sending, signing and tracking documents, with integrations for Microsoft 365, Salesforce and other business apps.

## Summary

Adobe Acrobat Sign scores 38 out of 100 (grade F) on the electronic signatures criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D+.

- Website: https://www.adobe.com/acrobat/business/sign.html
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Web, Android, iOS
- Category: [Electronic signatures](https://privacyratings.com/e-signatures/)
- Also rated: [Adobe Acrobat Reader](https://privacyratings.com/pdf-tools/adobe-acrobat-reader/) (PDF readers and editors), [Adobe Illustrator](https://privacyratings.com/creative-tools/adobe-illustrator/) (Creative tools), [Adobe Lightroom](https://privacyratings.com/creative-tools/adobe-lightroom/) (Creative tools), [Adobe Photoshop](https://privacyratings.com/creative-tools/adobe-photoshop/) (Creative tools), [Adobe Premiere](https://privacyratings.com/creative-tools/adobe-premiere/) (Creative tools)
- Grade: F (38/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. |  |
| No trackers or telemetry | No | The Android app includes 6 trackers, including Facebook Analytics, Demdex and Google Firebase Analytics. | https://reports.exodus-privacy.eu.org/en/reports/com.adobe.echosign/latest/ |
| No ads or data sales | No | Funded by subscriptions, but Adobe discloses information about actions in its websites and apps to social media and advertising partners. | https://www.adobe.com/privacy/policy.html |
| Independent audit | Partial | Adobe lists SOC 2 Type 2 among its compliance attestations. SOC 2 reports are shared with customers only under NDA. | https://www.adobe.com/trust/compliance/compliance-list.html |
| Transparency report | Yes | Publishes a yearly report with counts of government requests for user data. | https://www.adobe.com/trust/transparency/government-requests.html |
| Tells users about requests | Yes | Adobe gives advance notice to users targeted by a legal request unless a nondisclosure order prohibits it, and notifies them when the order expires. | https://www.adobe.com/trust/transparency/government-requests.html |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=secure.adobesign.com&hideResults=on |
| Security headers | No | Grade D+ (40/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=secure.adobesign.com |
| Modern web standards | Not tested yet | Not tested yet. |  |

Source: https://privacyratings.com/e-signatures/adobe-acrobat-sign/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/e-signatures/adobe-acrobat-sign.md
