Share your NDAs directly from Whistic.
Streamline your nondisclosure agreement workflows with DocuSign when sharing your security posture via Whistic.
Table of Contents
Summary
The Whistic + DocuSign integration helps companies proactively, securely, and efficiently share security documentation and makes it easy to use existing legal-approved NDAs from DocuSign to gate people accessing your security documentation. This ensures that only people who have signed the NDA via DocuSign will be able to view or download security documents.
This integration maintains DocuSign as the single source of truth for NDAs while allowing Whistic customers to send their NDAs automatically when sharing their security posture via Whistic. This improves efficiency and streamlines internal workflows by allowing Whistic users to reuse NDAs they already have in DocuSign.
🌟 Benefits
- One less step: Improves efficiency and streamlines internal workflows by allowing Whistic users to reuse NDAs they already have in DocuSign
- Automated NDA Requirement Bypass: Automatically bypass the NDA if it has already been signed via DocuSign (some restrictions apply)
- Fast and easy setup takes less than 5 minutes.
⚙️ How It Works
📄 Managing and Viewing NDAs from DocuSign
All editing, document management, viewing, and previewing of NDAs from DocuSign will be completed within DocuSign - not within Whistic.
You will be able to open a link from Whistic to view and edit DocuSign templates from Whistic in the Admin Tools > Company Settings > Non-Disclosure Agreements section of Whistic. However, all management of DocuSign documents will remain in DocuSign.
Templates to be used as NDAs in DocuSign must be set up with:
- A Document
- Signer - The role of "Signer" in DocuSign must be capitalized with a capital S
- Tabs for where to sign
- Select a Delivery option, but leave the email field blank
Sample screenshot
⚠️ Limitations
Automated NDA Bypass
After initial setup of this integration, when a Trust Center is shared, Whistic can check DocuSign to see if there is a signed NDA already captured in DocuSign in the previous 6 months. Due to limitations on the DocuSign side, Whistic cannot extend the look back period beyond 6 months. This is for initial shares sent after the DocuSign integration is set up only.
After the DocuSign integration is set up and an NDA is sent and signed via DocuSign, Whistic will be able to store that information - captured from the share event. If there are subsequent shares sent to recipients at this same company, Whistic will be able to verify that there is a NDA that has previously been signed via DocuSign with no limitations on the lookback period. This will bypass the NDA requirement for that specific NDA for all future recipients at that company.
NDA Status
NDA signature date will not be available to Whistic until the recipient views the Trust Center. At that time Whistic will be able to receive the signature date and reflect it within reporting, on the Trust Center and in Salesforce. The status will read as "Pending" until the Trust Center is viewed. Pending status will indicate that the NDA has been sent but not signed and/or the recipient has not yet viewed the Trust Center.
🚀 Getting Started
Prerequisites
- Must be a Whistic Admin access and be logged into Whistic
- Must have NDAs in templates within DocuSign to import
- Must have DocuSign Admin access and be logged into DocuSign
- Templates in DocuSign must be set up with:
- A Document
- Signer - The role of "Signer" in DocuSign must be capitalized with a capital S
- Tabs for where to sign
🔧 Setup
- Log into Whistic and DocuSign as an Admin. Complete the following steps starting in Whistic
- Under Settings menu (next to your name), select Integrations
-
In the Integrations listed, locate the Docusign tile and click Configure. (If you do not see DocuSign listed, then the feature hasn't been enabled on your account. Please reach out to your CSM or support for assistance with enabling this)
-
Click Connect to Docusign. Authenticate with DocuSign. You may have to select Allow Access or log into your DocuSign account. Once connected, you will receive the below success message.
- Now that DocuSign has been connected, select Enable on the integration.
-
Next, navigate to Settings then Trust Center Settings and scroll down to the Non-Disclosure agreements section and select the Import from DocuSign button.
-
In the window that pops up, select the NDA template(s) you wish to import and select Done. You can preview them if you'd like, however, this will redirect you into DocuSign for preview.
-
You will now see the various NDAs imported into your list under the source DocuSign.
-
You can now use one of the imported templates for your Trust Center by going to Trust Center > ellipsis (3 dots) menu > Trust Center Settings > Non-Disclosure Agreement (NDA) and selecting one from the list.
Here is a quick video walkthrough of the setup (UI may be outdated)
The following video provides a step-by-step guide to set up the integration between Whistic and DocuSign.
🔍 Troubleshooting
Deleted NDAs and Broken Connections between DocuSign and Whistic
In the event of a broken or disabled connection, or a deleted or archived NDA template, any active Whistic Trust Center, that is associated to an DocuSign template that is not available for these reasons, will be blocked from being shared until a the connection is restored and the NDA reapplied to the Trust Center or a different NDA is selected and applied to the Trust Center in the Trust Center settings. This will ensure that no Trust Center viewers will be able to access a Whistic Trust Center if an NDA is required without signing an available NDA.
The following indicators will be present to notify you if this occurs:
- An error will appear within the Trust Center settings instructing the user to select an available NDA to re-enable Trust Center sharing
- A tooltip will appear on the share button within Whistic in order to clearly denote a new NDA must be selected to re-enable sharing
- An email notification with details of the error will automatically be sent to the Whistic Administrator to let them know that there is an unavailable NDA from DocuSign and why.
Archiving a Template from Whistic
At this time, there is no way to delete a DocuSign template used as an NDA directly from Whistic. Currently, customers are unable to archive any NDA within the platform. If you wish to remove a template from Whistic, we recommend deleting it directly through DocuSign.
Versions & How to Identify
Whistic currently does not store specific versions of DocuSign templates. The latest version will be used automatically.
Common Emails Due to Failure to Send
1. The following email will be received if there is an issue with the template and signer information.
RESOLUTION: To resolve this issue, please review your Signer information in the template in DocuSign. In this example, there was an email address specified in the Signer's email field. This should be blank so as to be non-specific.
Sample screenshot
2. The following email will be received if the email from DocuSign is undeliverable for any reason.
RESOLUTION: Please go back and review the share to ensure that the proper contact information was entered. You will likely have to re-share your Trust Center to updated contact information to resolve this error.
For more details on these errors, it is encouraged that you log into your DocuSign account and view Reports>Envelope>Failed Delivery Report. As seen in the screenshot below:
❓ FAQ
What if a recipient already has a Trust Center link and they go to view the Trust Center and the NDA is not available?
In this case, the recipient will navigate to Whistic and, after registration, will be prompted to sign the NDA sent to their email address. An email will also be sent to the Whistic Administrator to let them know that the NDA is unavailable. To the recipient, it will look like they just did not get the NDA sent and this will persist until an available NDA is applied to the Trust Center, at which point it will be sent to the recipient for signature.
How can I resend the NDA to the recipient?
If the recipient tries to view the Trust Center and has not signed the NDA, there will be a splash screen letting them know that an NDA has been sent to them for signature and is required before they can access the Trust Center. When they see this splash screen, the NDA will automatically be resent to the recipient.