What proves a document was signed
A signature is only worth what stands behind it. Anyone can paste a picture of a name onto a page; what makes an agreement defensible is the record showing that a particular person was sent a particular document, agreed to sign it electronically, and did so at a particular time from a particular place.
Every completed Penstead request comes back as the signed PDF with a Certificate of Completion appended to it. Here is exactly what is on it.
On the certificate
- The document. Its title, its page count, the request ID, and when it was created.
- The original SHA-256. A fingerprint of the file as uploaded, before anybody touched it.
- Every signer. Name, the email address their link was sent to, and their affirmative consent to sign electronically — recorded at the moment they signed, not assumed from a checkbox on a terms page.
- The full event trail. Every sent, viewed, signed, declined, voided and completed event, timestamped, attributed to the person it belongs to, with the IP address and browser it came from.
The hash of the finished signed file is recorded against the request as well. Between the two, anyone holding a copy can verify it: hash the file, compare. The check does not require trusting us, which is the only sort of integrity claim worth printing.
A declined signature is still a record
If somebody refuses, the request stops and the certificate is issued marked VOIDED — with every event that led there still on it, including the signatures collected before the refusal. The awkward outcome is documented rather than absent, which is the case where a trail is worth most.
What this is not
This is an audit trail, not a qualified electronic signature under eIDAS, and Penstead is not a law firm. If you are signing something where the law names a specific standard — certain property transfers, some regulated filings, anything requiring a notary or a witness — that requirement does not go away because a document was signed online. Check what your jurisdiction asks for.
Common questions
- Is an electronic signature legally binding?
- In most places an electronic signature carries the same weight as a handwritten one for everyday agreements — that is what laws like the U.S. ESIGN Act and eIDAS in the EU exist to establish. Some documents are excluded almost everywhere, typically wills, some property transfers, and certain court and family-law filings. We are not lawyers and this is not legal advice: if the document matters, check what your jurisdiction requires for that specific kind of agreement.
- What actually makes a signature defensible?
- Not the image of the signature — anyone can paste one of those. What matters is the record around it: that a specific person, reachable at a specific address, was shown a specific document, consented to sign electronically, and acted at a specific time from a specific place. That record is the certificate, and it is why the hashes are on it.
- Do the hashes prove the document wasn’t altered?
- They let anyone check. The certificate prints the SHA-256 of the original upload, and the hash of the finished signed file is stored against the request. Anybody holding a copy can hash it themselves and compare — the check does not depend on trusting us, which is the only kind of integrity claim worth making.
- What happens if someone declines?
- The request stops, everyone who has already signed is recorded as having done so, and the certificate is issued marked VOIDED with the full trail intact. A refusal is part of the record rather than an absence from it.
- Do signers need an account to be in the audit trail?
- No. Signers never register. They open their own private link, and the trail records the address the link was sent to, when they opened it, when they signed, and from which IP.
The trail is on every request, on every plan, including the 5 a month that are free — it is not a feature held back for a higher tier. See pricing, or read how the preparation and sending fit together.