Skip to content

Audit trail

Electronic Signature Audit Trail on Every Document

An electronic signature audit trail is the time stamped record of who received, opened and signed a document, with email, IP address, browser and document hash. SignElectronically appends it to every completed PDF as a certificate.

Audit certificate

Certificate of completion

Sealed
EnvelopeClient services agreement
SHA-256 original9f2c 41ab 0e77 c3d5 … 8a10
SHA-256 final3b7e d902 5f1c a6e4 … 27cd
TimeEventIP
2026-10-08 14:00:12 UTCEnvelope sent to [email protected]203.0.113.24
2026-10-08 14:01:03 UTCEmail link opened, consent to electronic records given198.51.100.7
2026-10-08 14:02:40 UTCSigned by Maya Ross (email verified)198.51.100.7
2026-10-08 16:41:19 UTCSigned by Dan Lee (email code verified)203.0.113.24
2026-10-08 16:41:21 UTCDocument sealed, copies sent to all partiessystem

Anatomy

What the certificate records

Fields recorded in the audit certificate
Recorded item What it is Why it matters
Event and UTC timestamp Created, sent, opened, consent given, code verified, signed, declined, sealed, copy sent Shows the order of actions without time zone doubt
Signer email The address the personal signing link was sent to Attributes the action to a person
IP address and browser Network address and user agent of each action Supports attribution if a signer disputes it
Identity check Email link, and email or SMS one time code when required Shows how the signer was verified
SHA-256 of the original Fingerprint of the file you uploaded Proves which text was presented to sign
SHA-256 of the sealed PDF Fingerprint of the final file Lets anyone check the copy they hold
Event hash chain Each event carries the hash of the previous one Makes later changes to the log detectable

Tamper evidence

A log that shows if it was touched

A list of events in a database is only as good as the promise that nobody edited it. So each event here is hashed together with the hash of the event before it, starting from a fixed first value. The result is a chain.

If a timestamp were altered or a row removed, the hash of that row would change, and so would every hash after it. The check takes milliseconds and needs no trust in us beyond the published method.

The final PDF is also sealed with a certification signature that allows no changes. Open it in a common PDF reader and the signature panel reports whether the document was modified after sealing.

Hands turning to the last page of a stapled signed contract on a cluttered desk

Event chain, 2026-10-08 UTC

  1. Envelope sent14:00:12.204118

    prev 0000 0000 … 0000 hash a41c 9e07 … 5b2d

  2. Document opened14:01:03.551902

    prev a41c 9e07 … 5b2d hash 7f3a 18c2 … e940

  3. Consent to electronic records given14:01:09.870336

    prev 7f3a 18c2 … e940 hash c2d8 44b1 … 0a6f

  4. Signed14:02:40.012775

    prev c2d8 44b1 … 0a6f hash 19be f530 … 8c13

  5. Final PDF sealed16:41:21.660451

    prev 5e02 a7d9 … 31f4 hash 3b7e d902 … 27cd

Change or remove one row and every hash after it stops matching.

Check it yourself

Verify a signed PDF without an account

Verify a signed PDF

Match
Client services agreement, signed.pdf
SHA-256 of this file
3b7e d902 5f1c a6e4 … 27cd
Sealed on
2026-10-08 16:41:21 UTC
Signers
2 of 2 signed
Event chain
14 events, chain intact

This file is byte for byte the document that was sealed. Nothing changed after the last signature.

  1. 1

    Open the verify page

    Go to verify a signed PDF. No login is needed.

  2. 2

    Drop the file

    The page computes the SHA-256 hash of the file you hold and looks it up.

  3. 3

    Read the result

    A match shows when the document was sealed, how many people signed and whether the event chain is intact.

A counterparty, an auditor or a court clerk can run the same check. That is the point of evidence that does not depend on who presents it.

In a dispute

How the trail maps to what the law asks

Intent

The signer takes an explicit Sign action on a field assigned to them. The event is logged with time and IP.

Consent

Before signing, each person agrees to use electronic records. The consent is its own event.

Attribution

The link is personal to one email address, and a one time code can be required on Plus and Pro.

Retention

All parties get the sealed PDF and certificate, and you can download them at any time.

These four points come from US law, explained in our ESIGN Act and UETA guide. For the technical side of sealing and access control, read electronic signature security. The audit certificate is included in every plan on pricing, and you can see one after signing a PDF on the homepage.

Questions

Audit trail FAQ

It is the chronological record of everything that happened to a document sent for signature, including when it was sent, opened, consented to and signed, by which email address, from which IP address and browser. It is the evidence you rely on if a signature is ever questioned.

Get evidence with every signature

Every plan seals the final PDF and attaches the audit certificate, with no add-on to buy.

See pricing