Open Source Document Management: Paperless-NGX, Digital Signatures and Filing for Businesses

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

Want to digitise filing and signatures but not sure which system to use? WZ-IT's document management selection compares the matching open-source systems against your requirements. During the selection you try all candidates yourself in demo instances; the result is a decision paper, from €3,900 excl. VAT. Book a free initial consultation
Searching for open source document management mostly turns up lists of product names and many recommendations for private paperwork. Businesses face different questions: who may see which documents, how records stay unaltered, how contracts are signed, and what tax authorities and auditors require. A DMS is therefore rarely just one tool but the interplay of capture, filing, signature and retention.
This guide classifies open-source DMS by licence and release status, describes the strengths and limits of Paperless-ngx in a business setting, compares signature solutions with the eIDAS levels, and summarises what the German GoBD, retention periods and e-invoicing mean for filing. As of October 2026.
Key points at a glance:
- Paperless-ngx is the obvious candidate for small and medium-sized businesses. For larger environments, Mayan EDMS, LogicalDOC or Alfresco come into question.
- Several projects are barely maintained any more. Release status belongs in every selection.
- Documenso, DocuSeal and OpenSign sign on self-hosted infrastructure. The qualified signature always requires a trust service provider.
- No software is GoBD compliant on its own. What counts are permissions, immutability, logging and procedural documentation.
- E-invoices are retained in their original format, not just as a PDF.
Table of Contents
- What a DMS must deliver in a business
- Open-source DMS at a glance
- Paperless-ngx in a business: strengths and limits
- Digital signatures: Documenso, DocuSeal and OpenSign
- Signature levels under eIDAS and when the qualified signature is required
- GoBD and retention: what German rules require
- E-invoices in the DMS
- The interplay: capture, filing, signature, archive
- Selection criteria
- Common misconceptions
- Our approach at WZ-IT
- Further guides
What a DMS must deliver in a business
A network drive or file storage keeps files in folders. A document management system (DMS) captures documents, recognises their content and organises them by metadata rather than folder paths. The differences show in six tasks:
| Task | File storage (e.g. network drive) | DMS |
|---|---|---|
| Capture | file is saved | scan, mailbox or upload, automatic text recognition (OCR) |
| Organisation | folder structure, one location per document | metadata such as correspondent, document type, date, tags; one document in several views |
| Search | file name | full text and metadata |
| Permissions | per folder | per document, type or group |
| Traceability | usually none | history per document |
| Retention | manual | periods, archive format, protection against changes (depending on system and storage) |
For documents that are still being worked on, file storage such as Nextcloud with browser-based office remains the right place. The finished version goes into the DMS: the incoming invoice, the signed contract, the official notice.
Open-source DMS at a glance
| System | Licence | Latest release | Focus |
|---|---|---|---|
| Paperless-ngx | GPL-3.0 | v3.2.1 of 20 Sep 2026 | incoming mail, invoices, contracts in small and medium-sized businesses |
| Mayan EDMS | GPL-2.0 | 4.12.2 of 16 Sep 2026 | comprehensive DMS, designed for scalability according to the project |
| LogicalDOC Community Edition | LGPL-3.0 | 9.2 of 12 Aug 2025 | businesses, with roles, access control and activity logs |
| Alfresco Community Edition | LGPL-3.0 | 26.2.0 of 21 Jul 2026 | content repository for large environments |
| OpenDocMan | GPL-2.0 | v2.10.0 of 31 Aug 2026 | lean PHP DMS, oriented towards ISO 17025 |
| Docspell | AGPL-3.0 | v0.43.0 of 15 Mar 2025 | households and smaller groups or companies |
| Papermerge | Apache-2.0 | 3.5.3 of 18 Aug 2025 | scanned documents; project seeking maintainers |
| Teedy | GPL-2.0 | v1.11 of 12 Mar 2023 | lightweight DMS; no release since 2023 |
Sources: GitHub, Paperless-ngx, GitLab, Mayan EDMS, GitHub, LogicalDOC Community, GitHub, Alfresco Community Repository, GitHub, OpenDocMan, GitHub, Docspell, GitHub, Papermerge, GitHub, Teedy. As of October 2026.
Two notes on the table: release status is a selection criterion, because filed records must remain available for eight to ten years. And not every well-known DMS is open source: ecoDMS often appears in open-source lists but is commercially licensed, from EUR 89.00 including VAT (ecoDMS).
Paperless-ngx in a business: strengths and limits
Paperless-ngx is licensed under GPL-3.0; the current release is 3.2.1 of 20 September 2026. Functions according to the documentation:
| Function | Implementation |
|---|---|
| Text recognition | OCRmyPDF with Tesseract, more than 100 languages |
| Capture | upload and mail accounts with mail rules |
| Organisation | correspondent, document type, tags |
| Automation | workflows hook into processing, for example to set tags, document type or permissions automatically |
| Permissions | global and object permissions (view, edit) for users and groups |
| Search | full-text search, with a new search backend since version 3 |
| History | audit log, enabled by default, shown as history per document |
| Archive format | PDF/A-2b archive version alongside the original |
| AI | native AI since version 3.0.0, off by default, can run locally with Ollama |
Sources: Paperless-ngx, configuration, Paperless-ngx v3.0.0.
Three points matter for business use and are often overlooked:
- Archive version for scans only. Since version 3, Paperless-ngx creates the PDF/A archive version by default only for scanned and image-based documents. Born-digital PDFs with text remain as the original. The behaviour is controlled by the
PAPERLESS_ARCHIVE_FILE_GENERATIONsetting. - Deletion is possible. Users with delete permission can delete documents. They then remain in the trash for 30 days and are removed permanently afterwards (
PAPERLESS_EMPTY_TRASH_DELAY). Records subject to retention need a permission concept without delete rights and storage that prevents changes. - AI is optional. The native AI tags documents and answers questions about them but must be switched on explicitly. How this works locally without a cloud is described in Paperless-ngx AI setup.
The setup itself is shown in Paperless-ngx installation on Ubuntu.
Digital signatures: Documenso, DocuSeal and OpenSign
For electronic signing there are three open-source projects that can be self-hosted:
| Criterion | Documenso | DocuSeal | OpenSign |
|---|---|---|---|
| Licence | AGPL-3.0 | AGPL-3.0 with additional terms under section 7(b) | AGPL-3.0, one directory excepted |
| Current release | v2.19.0 of 29 Sep 2026 | 3.3.0 of 28 Sep 2026 | v2.41.3 of 21 Aug 2026 |
| Default signature | simple electronic signature with the instance certificate | electronic PDF signature with verification | audit trail and completion certificate |
| Advanced and qualified | since v2.13.0 through a trust service provider (Cloud Signature Consortium) | qualified through an external trust service provider, USD 2 per signature according to the vendor | not documented |
Sources: GitHub, Documenso, GitHub, DocuSeal, DocuSeal, qualified electronic signature, GitHub, OpenSign. As of October 2026.
With Documenso it pays to look at the code rather than only the documentation: the documentation page on signature levels still lists advanced and qualified signatures as planned, while they have been implemented since version 2.13.0 of 18 June 2026. A direct comparison of Documenso and DocuSeal is in Documenso or DocuSeal.
Signature levels under eIDAS and when the qualified signature is required
The eIDAS Regulation distinguishes three levels, last amended by Regulation (EU) 2024/1183, which entered into force on 20 May 2024.
| Level | Requirement | Reference | Legal effect |
|---|---|---|---|
| Simple electronic signature | data in electronic form used by the signatory to sign | Art. 3(10) | may not be denied legal effect solely because it is electronic (Art. 25(1)) |
| Advanced electronic signature | uniquely linked to the signatory, capable of identifying them, created under their sole control, subsequent changes detectable | Art. 3(11), Art. 26 | as above, higher evidential value |
| Qualified electronic signature | advanced signature with a qualified signature creation device and a qualified certificate | Art. 3(12) | equivalent legal effect to a handwritten signature (Art. 25(2)) |
Under German law, three provisions are decisive:
- Electronic form, section 126a BGB: where the law requires written form and permits the electronic form, only the qualified electronic signature replaces the handwritten signature.
- Text form, section 126b BGB: a legible declaration naming the person on a durable medium. Any signature level is sufficient here.
- Exclusion of the electronic form: some declarations require paper, such as terminating an employment relationship and termination agreements under section 623 BGB.
For quotes, orders, internal approvals and many contracts without form requirements, the simple or advanced signature is sufficient. Whether a specific document requires a particular form is a legal question.
Not legal advice. Consult legal counsel for specific questions on form requirements. Trademarks belong to their owners.
GoBD and retention: what German rules require
The German principles for the proper keeping and retention of books, records and documents in electronic form (GoBD) are set out in the Federal Ministry of Finance letter of 28 November 2019, amended on 11 March 2024 and 14 July 2025, most recently mainly because of e-invoicing (Federal Ministry of Finance, GoBD as amended on 14 July 2025). Four points matter for a DMS:
| Requirement | Content | Paragraph |
|---|---|---|
| Immutability | The original content must remain determinable; changes and deletions are logged. | paras. 58, 59 |
| File system | Filing in a file system regularly does not meet immutability without additional measures. | para. 110 |
| Procedural documentation | For every IT system a clearly structured documentation, with general description, user, technical system and operations documentation. | paras. 151, 153 |
| Certificates | The tax authorities issue no positive attestations; certificates or attestations from third parties do not bind the tax authority. | paras. 180, 181 |
The consequence: whether filing meets the GoBD depends on the entire procedure, not on the product. Technically this includes a permission concept without delete rights for records subject to retention, logging of changes, storage that prevents changes (such as object storage with Object Lock), a separate backup and procedural documentation.
Retention periods under section 147 of the Fiscal Code (AO) as amended from 1 January 2025:
| Records | Period |
|---|---|
| Books, records, annual financial statements, inventories | 10 years |
| Accounting vouchers | 8 years (banks, insurers, investment firms: 10 years) |
| Invoices (section 14b UStG) | 8 years |
| Commercial and business letters received and sent | 6 years |
The shorter period for accounting vouchers applies to all records whose period had not yet expired on 31 December 2024 (Art. 97 section 19a EGAO). Section 257 HGB contains the corresponding commercial-law periods.
Not tax advice. Agree the procedural documentation and the classification of individual records with your tax adviser.
E-invoices in the DMS
Since 1 January 2025, domestic businesses in Germany must be able to receive e-invoices (section 14 UStG). For issuing, transitional rules apply under section 27(38) UStG:
| Period | Rule |
|---|---|
| until 31 Dec 2026 | paper invoices or, with the recipient's consent, other electronic formats still possible |
| until 31 Dec 2027 | other formats still possible if prior-year turnover did not exceed EUR 800,000; EDI procedures also until end of 2027 |
What matters for filing: the structured part of the e-invoice (the XML) must be retained unaltered in its original form. For hybrid formats such as ZUGFeRD, the PDF part only needs to be retained as well if it contains additional tax-relevant information, such as booking notes (GoBD para. 131 as amended on 14 July 2025).
A DMS that only displays e-invoices as PDF or creates an archive copy is not sufficient for this. The XML must be filed as the original and remain retrievable. Paperless-ngx keeps the original; whether processing of the respective e-invoice format meets the requirements should be tested with real invoices.
The interplay: capture, filing, signature, archive
In a business, individual tools form a process:
| Step | Tool (example) | Result |
|---|---|---|
| Capture | scanner, mailbox, upload | document in the DMS with recognised text |
| Classification | workflows, rules, optionally AI | correspondent, document type, tags, permissions |
| Editing | Nextcloud with browser-based office | draft that several people work on |
| Signature | Documenso or DocuSeal | signed PDF with audit log |
| Filing | DMS | finished document with metadata, searchable |
| Retention | storage with change protection, backup | unaltered records for the retention period |
| Sign-in | identity service with single sign-on | one account for all tools |
For automatically extracting invoices and delivery notes there are additional self-hostable AI methods. An overview is in Self-hosted AI document processing.
Selection criteria
| Criterion | Question |
|---|---|
| Document types | Incoming mail and invoices, contracts, personnel files, technical documentation? |
| Permissions | Are permissions per document and group enough, or are tenants and department boundaries needed? |
| Retention | How are deletion and changes prevented for records subject to retention? |
| E-invoices | Is the XML filed and displayed in its original form? |
| Integrations | Scanner, mail, accounting, ERP, identity service? |
| Signature | Which level is needed, and where does the signed document end up? |
| Project maintenance | When was the last release, how active is development? |
| Operation | Who handles updates, backups and restore tests across the retention periods? |
Common misconceptions
| Misconception | Correct is |
|---|---|
| "Paperless-ngx is GoBD certified." | There is no official GoBD certification. Third-party certificates do not bind the tax authority (GoBD para. 181). |
| "Open-source DMS are free." | The licence is free. Setup, migration, operation and backups still cost money. |
| "ecoDMS is open source." | ecoDMS is commercially licensed. |
| "Paperless-ngx stores everything as PDF/A." | Since version 3 only scans and image-based documents by default. The original is always kept. |
| "Contracts signed with Documenso replace every signature." | The default is the simple electronic signature. Where written form is required, the qualified signature is needed, and for some declarations paper. |
| "Filing the e-invoice as a PDF is enough." | The structured part must be retained in its original format. |
| "A network drive with folders is enough for records." | Filing in a file system regularly does not meet immutability without additional measures (GoBD para. 110). |
Our approach at WZ-IT
WZ-IT supports document management from selection to operation. Every step has a defined result.
- Selection with a defined scope. The document management selection costs from EUR 3,900 net. It covers an assessment of your document types and processes, weighted criteria with business units and IT, and a review of licence, signature and operating limits. For the duration of the selection we provide demo instances of all candidates, which you try out yourself with your own sample documents without committing first. The result is a decision paper with a recommendation for DMS and signature, migration path and operating model. If a different solution fits better, the paper says so. The amount is credited towards the rollout if you commission it within 6 months on the same topic.
- Rollout. You receive the quote for this together with the decision paper. Depending on the selection it covers setup, permission concept, connecting scanners, mailboxes and single sign-on, and migrating existing filing.
- Operation in Germany. We operate the system via Managed Open Source in German data centres, from EUR 129.90 net per workload per month, with updates, backups and monitoring. Alternatively it runs on your own infrastructure.
Procedural documentation and tax classification remain with you and your tax adviser. All entry points from the free initial consultation to the selection are listed on the page Consulting at WZ-IT.
Further guides
- Paperless-ngx AI setup, the native AI from version 3 locally with Ollama.
- Paperless-ngx installation on Ubuntu, setup with Caddy and SSL.
- Documenso or DocuSeal, electronic signing on your own infrastructure.
- Self-hosted AI document processing, processing invoices and delivery notes on your own infrastructure.
- Nextcloud, Seafile, OpenCloud or ownCloud, file storage for documents in progress.
- Document management selection, WZ-IT's package.
Digitise filing and signatures with open source. We clarify document types, permissions and retention with you, let you try the matching systems yourself in demo instances, and support rollout and operation. Book a free initial consultation
Sources
- GitHub, Paperless-ngx
- Paperless-ngx, configuration
- Paperless-ngx, usage
- GitHub, Paperless-ngx v3.0.0
- GitLab, Mayan EDMS
- GitHub, LogicalDOC Community
- GitHub, Alfresco Community Repository
- GitHub, OpenDocMan
- GitHub, Docspell
- GitHub, Papermerge
- GitHub, Teedy
- ecoDMS
- GitHub, Documenso
- GitHub, DocuSeal
- DocuSeal, qualified electronic signature
- GitHub, OpenSign
- EUR-Lex, eIDAS Regulation (consolidated)
- Section 126a BGB (German)
- Section 126b BGB (German)
- Section 623 BGB (German)
- Federal Ministry of Finance, GoBD as amended on 14 July 2025 (German)
- Section 147 AO (German)
- Art. 97 section 19a EGAO (German)
- Section 257 HGB (German)
- Section 14 UStG (German)
- Section 14b UStG (German)
- Section 27 UStG (German)
Introduce document management with open source
We compare the matching open-source systems for filing and signatures against your requirements, provide demo instances for you to try out yourself, and support rollout and operation in Germany.
Frequently Asked Questions
Answers to important questions about this topic
It depends on size and requirements. Paperless-ngx (GPL-3.0) is built for incoming mail, invoices and contracts and is the obvious candidate for small and medium-sized businesses. Mayan EDMS (GPL-2.0), LogicalDOC Community Edition (LGPL-3.0) and Alfresco Community (LGPL-3.0) tend to target larger environments. What matters are permissions, retention, integrations and whether the project is actively maintained.
The software has no licence fees. Costs arise for setup, migrating existing documents, servers, backups and operation, and for qualified signatures additionally for the trust service provider. Note that ecoDMS is not an open-source product but commercially licensed, from EUR 89.00 including VAT (as of October 2026).
No software is GoBD compliant on its own. The German GoBD require, among other things, immutability, logging of changes and procedural documentation for every IT system. Paperless-ngx provides building blocks for this, such as an audit log enabled by default and retention of the original. Users with delete permission can, however, delete documents, permanently after 30 days in the trash. A permission concept, immutable storage and procedural documentation are needed on top. Not tax or legal advice.
No. According to GoBD para. 180, the German tax authorities do not issue positive attestations, neither in tax audits nor as binding rulings. Under para. 181, certificates or attestations from third parties have no binding effect on the tax authority. Vendor statements such as 'GoBD compliant' are statements by the vendor.
Under section 147 of the German Fiscal Code as amended from 1 January 2025: accounting vouchers 8 years, books, annual financial statements and inventories 10 years, commercial and business letters 6 years. Invoices under section 14b of the VAT Act 8 years. For banks, insurers and investment firms, accounting vouchers remain at 10 years. Not tax advice.
For receiving, which all domestic businesses in Germany must be able to do since 1 January 2025, retention is what matters: the structured part of the e-invoice (XML) must be kept unaltered in its original form. A DMS that only stores a PDF or an archive copy is not sufficient for that. The original format must be filed as well. Not tax advice.
The best known are Documenso, DocuSeal and OpenSign, all under AGPL-3.0 (some with additional terms). Documenso signs with a simple electronic signature by default and has supported advanced and qualified signatures through a trust service provider since version 2.13.0. DocuSeal offers qualified signatures through an external trust service provider (as of October 2026).
When German law requires written form and permits the electronic form: under section 126a of the German Civil Code, only the qualified electronic signature then replaces a handwritten signature. Many business transactions need only a simple or advanced signature. Some declarations do not permit the electronic form at all, such as terminating an employment relationship under section 623 of the Civil Code. Not legal advice.
No, not any more. Since version 3, Paperless-ngx creates the PDF/A archive version by default only for scanned and image-based documents. Born-digital PDFs with embedded text do not get an archive version. The original is retained in every case.
Only partly. Nextcloud is file storage with sharing, sync and browser-based office and suits documents that are still being worked on. A DMS such as Paperless-ngx captures finished documents with OCR, organises them by metadata such as correspondent and document type, and makes them searchable. The two are often combined.
Yes, since version 3.0.0 there is a native AI feature. It is disabled by default and must be switched on explicitly. It can run locally with Ollama, so documents do not leave your own system.
Yes. In WZ-IT's document management selection, demo instances of all candidates are available for the duration of the selection, and you try them out yourself with your own sample documents. The selection costs from EUR 3,900 net, and the result is a decision paper. The amount is credited towards the rollout if you commission it within 6 months on the same topic.

Written by
Timo Wevelsiep
Co-Founder & CEO
Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.
LinkedInLet's Talk About Your Idea
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.





