Is Docusign PKI safe?

Low risk

DocuSign PKI writes the extension's runtime ID into the DOM on DocuSign signing pages, where other scripts on that page can read it.

The extension bridges DocuSign signing pages to a locally installed DocuSign PKI native app using Chrome's native messaging API. Content scripts run only on DocuSign signing pages (*.docusign.com, .net, .mil). As part of its handshake mechanism, the extension inserts a hidden div containing its Chrome runtime ID, which any other JavaScript on the same DocuSign page — including third-party analytics or scripts injected by an XSS — can read to confirm the extension is installed.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

DocuSign Inc.v25.1.00.00Chrome Web Store
17Risk
Who publishes it

Docusign - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
DocuSign Inc.
Declared legal entity
Docusign
Registered address
221 Main St #1000, San Francisco, CA 94105-1925, US
Registered contact
Docusign, Inc.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 25.1.00.00. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed DocuSign PKI contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • com.docusign.chrome.sign

    DocuSign PKI sends data to com.docusign.chrome.sign. No other extension we have analysed sends data here.

Updated 30 September 2026hcclkhcbkkdkaedoogloknhdbkjjgdem