Audit trailFree and up

Prove who signed, when, and that nothing changed

Every view, field completion, and signature is recorded with identity, IP, and timestamp, then sealed with a cryptographic hash. The certificate is embedded in the signed PDF, so it stays verifiable without us.

When an electronic signature is disputed, the argument is almost never whether e-signatures are valid — that is settled law. The argument is one of four claims: that was not me, I never agreed to that version, I did not know I was signing, or that is not when it happened.

Every field in our certificate exists to answer one of those four. If a field does not help with any of them, we do not collect it.

How it works

Step by step

  1. 1

    We hash the document at send

    A SHA-256 hash of the document bytes is recorded before any signing happens. That gives you a before-and-after pair, proving that what the signer saw is what ended up in the final file.

  2. 2

    Every interaction is logged in sequence

    Sent, delivered, opened, viewed per page with duration, each field completed, signed or declined. Page view duration is the most frequently cited evidence in disputes — "I never saw clause 12" is hard to sustain when the record shows page four open for ninety seconds.

  3. 3

    Completion seals the document

    A second SHA-256 hash is computed over the final bytes, and the certificate is signed with our private key. Change one digit in a payment amount and the hash will not match. There is no partial match and no way to construct a different document with the same hash.

  4. 4

    The certificate travels with the file

    It is attached as a final page to the completed document and separately downloadable. Generated once and never regenerated, so the copy you download in three years is byte-identical to day one — and verifiable by anyone, without needing an account with us.

What it supports

SHA-256 hash at send and at completion, independently verifiable
Per-page view events with duration, per recipient
Electronic-records consent capture with timestamp, as ESIGN requires
IP address and coarse geolocation per event; browser and OS per session
Conditional logic evaluations recorded with inputs and outcome
Optional RFC 3161 trusted timestamps from an independent authority
Who it's for

Where this matters most

Availability & limits

Free and up

Basic audit trail on Free. The full court-admissible certificate is Pro and Business.

Worth knowing
  • Free plan records core events but not per-page view durations
  • RFC 3161 trusted timestamps are a Business add-on
  • IP is corroborating evidence, not conclusive — it can be shared, proxied, or mobile
  • No audit trail can prove who was physically holding the device; nothing can, short of in-person verification
Compare plans →
Questions

Audit trail, specifically

We do not fingerprint devices beyond browser and OS strings, do not track signers across other sites, do not record precise GPS even where a browser would offer it, and do not retain verification code contents. Every extra field is data that must be secured, disclosed, and eventually deleted.

Works well with

Ready to try it?

Sign a sample document in under a minute — no signup required.

Open the live demo →