Skip to content

Security

Electronic Signature Security You Can Inspect

Electronic signature security rests on three things, a verified signer, a document that cannot change unnoticed and a record nobody can quietly rewrite. Here is how SignElectronically handles each one, described as concrete measures and without certificates we do not hold.

IT administrator checking access settings on a laptop in a server closet

The document

Sealed, hashed and checkable by anyone

When the last signer finishes, the PDF is sealed with a certification signature made with the platform seal certificate. The seal is set to allow no changes. If anyone edits the file afterwards, the signature panel of a PDF reader reports that the document was modified.

Two SHA-256 fingerprints are recorded, one of the original upload and one of the sealed result. The second one powers the public verify page, where anyone holding a copy can confirm it matches our record byte for byte.

Uploaded PDFs are rewritten into a clean structure before use, and files that cannot be parsed safely are rejected instead of being passed on to signers.

Verify a signed PDF

Match
Client services agreement, signed.pdf
SHA-256 of this file
3b7e d902 5f1c a6e4 … 27cd
Sealed on
2026-10-08 16:41:21 UTC
Signers
2 of 2 signed
Event chain
14 events, chain intact

This file is byte for byte the document that was sealed. Nothing changed after the last signature.

The record

An event log that cannot be edited quietly

Event chain, 2026-10-08 UTC

  1. Envelope sent14:00:12.204118

    prev 0000 0000 … 0000 hash a41c 9e07 … 5b2d

  2. Document opened14:01:03.551902

    prev a41c 9e07 … 5b2d hash 7f3a 18c2 … e940

  3. Consent to electronic records given14:01:09.870336

    prev 7f3a 18c2 … e940 hash c2d8 44b1 … 0a6f

  4. Signed14:02:40.012775

    prev c2d8 44b1 … 0a6f hash 19be f530 … 8c13

  5. Final PDF sealed16:41:21.660451

    prev 5e02 a7d9 … 31f4 hash 3b7e d902 … 27cd

Change or remove one row and every hash after it stops matching.

Every action on an envelope is written to an append only log with a UTC timestamp to the microsecond, IP address, browser and email. Each row stores the hash of the previous row, and its own hash covers all of its fields.

Altering or deleting one event breaks the chain from that point on. The certificate attached to the PDF is produced from this log. Details are on the electronic signature audit trail page.

People

Signers and team members are verified separately

Personal signing links

Each signer gets a unique link. Only its SHA-256 hash is stored, so a copy of the database does not reveal working links.

One time codes

Codes sent to signers are stored hashed, expire after 10 minutes and lock after 5 wrong attempts. A new code can be requested once a minute.

Passwords and two factor login

Account passwords are stored only as salted hashes. Team members can turn on two factor login with an authenticator app, and Pro can require it for everyone.

Team isolation and roles

Every envelope, template, file and API key belongs to one team, and access is checked against membership. Roles separate owners, admins, senders and viewers.

API keys and webhook secrets

API keys are stored as hashes and shown once. Webhook secrets are encrypted in the database, and each delivery is signed with HMAC SHA-256.

Login and form protection

Sign in is rate limited per account and IP address. Sign up, password reset and signer code forms carry bot protection.

Summary

Measures at a glance

Security measures and where they apply
Area Measure Plans
Transport HTTPS for every page and API call, with strict transport security and headers against framing and content sniffing All
Storage Documents on private storage that is not reachable by a public address, served only through access checked downloads All
Integrity Certification seal on the final PDF, SHA-256 of original and result, hash chained event log All
Signer identity Personal email link All
Signer identity One time code by email or SMS Plus and above
Team access Roles, folders, activity log Plus and above
Team access SAML single sign-on, enforced two factor login Pro and above
Data lifecycle Retention rules with automatic deletion, audit log export Pro and above
Organisation Dedicated EU or US data region, SCIM provisioning, security review package Enterprise

Plainly stated

What we do not claim

  • No SOC 2, ISO 27001 or HIPAA certification is claimed
  • No qualified electronic signatures (QES) under eIDAS, and no notarisation
  • The seal certificate is our own platform certificate, not one issued by a qualified trust service provider
  • Identity checks confirm control of an email address or phone number, not a government ID

If your documents need a qualified signature or an ID check, you need a different class of service, and we would rather say so here than in a dispute. The eIDAS advanced electronic signature page explains the levels.

To report a vulnerability, write to [email protected]. How we handle personal data is in the privacy policy. Product overview on the homepage.

Questions

Electronic signature security FAQ

An electronic signature is as secure as the process around it. The important parts are that the signer is verified, the document cannot change unnoticed after signing, and there is an independent record of what happened. On this page we describe how each of those is handled here.

See the seal on your own document

Send a document, open the sealed PDF in any reader and check it on the verify page.

See pricing