Skip to main content

Legal

Compliance

What we can honestly claim about the legal standing of signatures made here, and what we cannot.

Last updated August 2026.

What makes a signature defensible

An electronic signature is only useful if you can later show who made it, that they meant to, and that the document has not changed since. Everything below exists to support those three claims.

  • Identity: every signer receives a one-time code at their email address and must enter it before their signature is recorded.
  • Intent: the signer is shown the document and must actively consent before signing.
  • Integrity: the finished file is hashed with SHA-256, and anyone can check a copy against that hash on our public verification page.
  • Evidence: every action is written to an append-only audit trail with timestamp, IP address and browser, and reproduced on the certificate of completion.

eIDAS (European Union)

Signatures made here are Advanced Electronic Signatures in the sense of eIDAS: uniquely linked to the signer, capable of identifying them, created using means under their sole control, and linked to the document such that later changes are detectable.

They are not Qualified Electronic Signatures. A QES requires a certificate issued by a qualified trust service provider and a qualified signature creation device. We do not issue those, and any vendor telling you a plain email-and-code flow produces a QES is wrong.

ESIGN and UETA (United States)

The ESIGN Act and UETA make a signature valid regardless of the form it takes, provided the signer intended to sign and consented to do so electronically, and provided the record can be retained and reproduced.

Our flow captures consent explicitly, records intent, and produces a retainable sealed copy with its audit trail attached.

Saudi Arabia and the GCC

The Saudi Electronic Transactions Law recognises electronic signatures and the records supporting them. Comparable laws exist across the GCC.

Some transactions require a certificate from a licensed provider. Where your transaction does, this platform on its own is not sufficient, and you should not assume otherwise because a signature completed successfully.

What we do not claim

We would rather be useful than impressive, so:

  • We are not a qualified or licensed trust service provider in any jurisdiction.
  • We do not issue digital certificates and do not apply cryptographic PKI signatures to the PDF itself. Integrity is established by hash and audit trail, which is a different mechanism with different properties.
  • We hold no third-party audit certification such as SOC 2 or ISO 27001 today. When that changes, this page will say so and name the auditor and the date.
  • Some documents cannot be signed electronically at all in some places — wills, certain property transfers, some family law instruments. Checking that is your responsibility.

Data residency

Where your documents are stored depends on how your instance is configured. If residency in a particular country is a requirement for you, ask us before you rely on it rather than after.

Reporting a security problem

If you find a weakness, tell us at the security address below. We will acknowledge it, tell you what we found, and credit you if you would like us to. We will not threaten you for reporting it.