Security
Electronic Signature Security You Can Inspect
Electronic signature security rests on three things, a verified signer, a document that cannot change unnoticed and a record nobody can quietly rewrite. Here is how SignElectronically handles each one, described as concrete measures and without certificates we do not hold.

The document
Sealed, hashed and checkable by anyone
When the last signer finishes, the PDF is sealed with a certification signature made with the platform seal certificate. The seal is set to allow no changes. If anyone edits the file afterwards, the signature panel of a PDF reader reports that the document was modified.
Two SHA-256 fingerprints are recorded, one of the original upload and one of the sealed result. The second one powers the public verify page, where anyone holding a copy can confirm it matches our record byte for byte.
Uploaded PDFs are rewritten into a clean structure before use, and files that cannot be parsed safely are rejected instead of being passed on to signers.
Verify a signed PDF
Match- SHA-256 of this file
- 3b7e d902 5f1c a6e4 … 27cd
- Sealed on
- 2026-10-08 16:41:21 UTC
- Signers
- 2 of 2 signed
- Event chain
- 14 events, chain intact
This file is byte for byte the document that was sealed. Nothing changed after the last signature.
The record
An event log that cannot be edited quietly
Event chain, 2026-10-08 UTC
-
Envelope sent14:00:12.204118
prev 0000 0000 … 0000 hash a41c 9e07 … 5b2d
-
Document opened14:01:03.551902
prev a41c 9e07 … 5b2d hash 7f3a 18c2 … e940
-
Consent to electronic records given14:01:09.870336
prev 7f3a 18c2 … e940 hash c2d8 44b1 … 0a6f
-
Signed14:02:40.012775
prev c2d8 44b1 … 0a6f hash 19be f530 … 8c13
-
Final PDF sealed16:41:21.660451
prev 5e02 a7d9 … 31f4 hash 3b7e d902 … 27cd
Change or remove one row and every hash after it stops matching.
Every action on an envelope is written to an append only log with a UTC timestamp to the microsecond, IP address, browser and email. Each row stores the hash of the previous row, and its own hash covers all of its fields.
Altering or deleting one event breaks the chain from that point on. The certificate attached to the PDF is produced from this log. Details are on the electronic signature audit trail page.
People
Signers and team members are verified separately
Personal signing links
One time codes
Passwords and two factor login
Team isolation and roles
API keys and webhook secrets
Login and form protection
Summary
Measures at a glance
| Area | Measure | Plans |
|---|---|---|
| Transport | HTTPS for every page and API call, with strict transport security and headers against framing and content sniffing | All |
| Storage | Documents on private storage that is not reachable by a public address, served only through access checked downloads | All |
| Integrity | Certification seal on the final PDF, SHA-256 of original and result, hash chained event log | All |
| Signer identity | Personal email link | All |
| Signer identity | One time code by email or SMS | Plus and above |
| Team access | Roles, folders, activity log | Plus and above |
| Team access | SAML single sign-on, enforced two factor login | Pro and above |
| Data lifecycle | Retention rules with automatic deletion, audit log export | Pro and above |
| Organisation | Dedicated EU or US data region, SCIM provisioning, security review package | Enterprise |
Plainly stated
What we do not claim
- No SOC 2, ISO 27001 or HIPAA certification is claimed
- No qualified electronic signatures (QES) under eIDAS, and no notarisation
- The seal certificate is our own platform certificate, not one issued by a qualified trust service provider
- Identity checks confirm control of an email address or phone number, not a government ID
If your documents need a qualified signature or an ID check, you need a different class of service, and we would rather say so here than in a dispute. The eIDAS advanced electronic signature page explains the levels.
To report a vulnerability, write to [email protected]. How we handle personal data is in the privacy policy. Product overview on the homepage.
Questions
Electronic signature security FAQ
See the seal on your own document
Send a document, open the sealed PDF in any reader and check it on the verify page.