Skip to content
Browse help

What an electronic signature from CecurSign is

What we produce, what stands behind it, and what we deliberately do not offer.

Last updated

CecurSign produces a simple electronic signature, in the sense of Regulation (EU) 910/2014 (eIDAS) and the corresponding UK legislation, with an unusually strong evidence record standing behind it. We do not issue a personal signing certificate to each signer, and we do not provide advanced or qualified electronic signatures. This page sets out what you get, so you and your adviser can decide what to use it for.

What we capture

Your recipient signs by drawing a signature, typing one, or reusing a saved one. When the last person on an envelope (the document you sent out for signature, together with the people asked to sign it) has finished, we produce a completed PDF with the signatures and every other answer placed into the pages and fixed there.

We record a fingerprint of that finished file, and we check it again every time the file is read. If the bytes ever stop matching the fingerprint of record, the file is refused rather than served.

What stands behind it

A tamper-evident audit trail. Every action on an envelope is recorded as a numbered event, and each event carries a fingerprint that includes the fingerprint of the event before it. Altering an earlier event changes its fingerprint and breaks every event after it, and removing one leaves a gap in the numbering. The time, IP address and browser of each action are held inside the protected record rather than beside it, so the surrounding detail is as tamper-evident as the event itself. See The audit trail.

A record of what the signer agreed to. Consent to sign electronically is a separate, deliberate step, and the exact sentence shown to the signer is written into the audit trail along with the version of that wording. The record shows not only that somebody consented but what they were reading when they did.

Independent timestamping. The head of the chain is regularly timestamped against several external timestamp authorities using RFC 3161, and the raw tokens are kept. That anchors the record in time against something other than our own servers and our own clock. These are public timestamp authorities rather than qualified trust service providers, which is part of why we describe the signature as simple, and it is the certificate that tells you which of the two applies to your document.

A certificate of completion. Every finished document carries one. It lists each signature with its time, actor and IP address, a fingerprint for every document in the set, and the full sequence of recorded events, and it carries a QR code leading to an independent check. See The certificate of completion.

A check anyone can run. Anybody holding the reference printed on that certificate can verify the document at cecursign.io/verify with no account and no login. They see whether the chain is intact, who signed and when, and how many events are recorded. When your client hands it to their bank, their solicitor or their auditor, that third party can confirm it without coming back to you. See Checking that a signed document is genuine.

An evidence pack. One download gives you the original files, the signed version, the certificate, the complete audit trail, the signature images and the timestamp tokens.

What we deliberately do not offer

A certificate-based signature inside the PDF. Opened in Adobe Acrobat, a completed document shows no signature panel, and that is expected rather than a fault. The evidence lives in the audit trail, the certificate and the verification page, which is where it can be examined by anyone.

Advanced or qualified electronic signatures. If a particular instrument requires one, it needs a qualified provider.

Identity verification. We confirm control of the email address you addressed the document to, and an access code where you set one. That is not proof of who somebody is. If your obligations require identity checks, carry them out the way you do today and use CecurSign for the agreement itself. See Protecting a document with an access code.

Legal advice. Whether a simple electronic signature suits a given document, and whether that document attracts formalities such as witnessing or execution as a deed, is a question for you and your adviser. See our Terms of Service.