Security and evidence
Every signature,backed by evidence.
See what is recorded, how changes are detected, and what a third party can verify without an account.
CecurSign
Certificate of Completion
Envelope information
- Envelope ID
- 9c1f2a34-5b6d-4e71-8f90-2ad4c6e13b58
- Subject
- Letter of engagement 2026/27
- Created
- 04/06/2026 09:12 UTC
- Sent
- 04/06/2026 09:14 UTC
- Completed
- 05/06/2026 16:41 UTC
Documents
Engagement letter and schedules.pdf (7 pages)
SHA-256: a4f1c9e0b7d3
Signers and recipients
- R. Hartley (Signer)Signed 04/06/2026 11:02 UTC
- J. Okafor (Signer)Signed 05/06/2026 16:41 UTC
Scan to verify
Envelope ID
9c1f2a34-5b6d-4e71-8f90-2ad4c6e13b58
The audit trail is a chain, not a log
A log is a list of things that happened. A chain is a list that cannot be quietly edited.
Every event on a document (created, sent, opened, signed, declined) is recorded with a fingerprint that includes the fingerprint of the event before it. The records form a chain, and each one is numbered in sequence.
That structure is what makes tampering detectable. Altering an earlier event changes its fingerprint, which breaks every event after it. Removing one leaves a gap in the numbering.
Verification does not simply pass or fail. It reports which event broke the chain and in what way: a missing sequence number, a mismatched link, or a record whose own contents no longer match its fingerprint.
The time, IP address and browser of each action are recorded inside the protected record rather than alongside it, so the surrounding detail is as tamper-evident as the event itself. Most systems log this information; the word doing the work here is inside.
Events are written under a lock that serialises them per document, so two things happening at once cannot produce two records claiming the same position in the chain. Each document also carries its own fingerprint, and it is re-checked every time the file is read. If the bytes no longer match, the file is refused rather than served.
- 1
Envelope sent
04/06/2026 09:14
- previous
- none
- this record
- 7b21e9
- 2
Opened by recipient
04/06/2026 10:47
- previous
- 7b21e9
- this record
- c40f83
- 3
Signed
04/06/2026 11:02
- previous
- c40f83
- this record
- 1de6a5
- 4
Completed
05/06/2026 16:41
- previous
- 1de6a5
- this record
- 9af02c
Each record carries the fingerprint of the record before it. Change event 2 and events 3 and 4 stop matching, so re-checking the chain reports which record broke rather than simply failing.
Anyone can check a completed document
Without an account, without a login, and without coming back to you.
Every completed document produces a certificate of completion. It lists each signature with its time, actor and IP address, a fingerprint for every document in the set, and the full sequence of recorded events. It carries a QR code that leads to an independent check.
That check is public by design. When your client hands the document to their bank, their solicitor or their auditor, that third party can confirm it themselves: the chain is intact, these people signed, at these times. It converts an assertion into something the reader can test.
If a document is ever disputed, the evidence pack is a single download: the original files, the signed version, the certificate, the complete audit trail and every signature image.
This document’s verification passed
The signing process is complete and the recorded audit chain is intact.
- Sent by
- Hartley & Co
- Document
- Letter of engagement 2026/27
- Recipients
- 2
- Audit events
- 14
- Signing completedConfirmedThe envelope reached its completed signing state.
- Audit chain intactConfirmedAll 14 events recomputed without a break.
- Certificate recordedConfirmedA completion certificate is available for this envelope.
Access, identity and secrets
Signer identity
You can require an access code, which you give the signer yourself, by phone or in person. It never appears in the email, or it would not be a second check. The code is a shared secret you choose and can look up again, so treat it as one. It is compared in constant time, five wrong attempts lock the document for fifteen minutes, and every attempt is recorded.
Credentials
Passwords are hashed with Argon2id at a deliberately high memory cost. API keys are generated with 192 bits of randomness and stored only as digests, so we cannot show you an existing key, only issue a new one. Signing links use 256-bit tokens.
Separation
Every query is scoped to your organisation. Within it, visibility is set independently of role (own documents, department, or organisation-wide) and applied to evidence and notifications too, not just to lists.
What we do not do
We do not verify identity documents. A one-time code proves someone holds a phone or an email account. It does not prove who they are. If your obligations require identity verification, whether that is anti-money laundering checks or right-to-work verification, do it the way you do today and use this for the agreement itself.
We do not provide qualified electronic signatures. These are simple electronic signatures with strong evidence behind them, which is sufficient for the documents most companies send. If a specific instrument requires a qualified signature, it needs a qualified provider.
We do not accept files from signers. Recipients sign, type, tick and date. They cannot upload a document back to you through the signing page.
We do not take payment when a document is signed. Getting the agreement signed and collecting money are separate, and we only do the first.
Common questions
What class of electronic signature is this?
Can you alter an audit trail?
What can a third party check without contacting us?
Who inside my company can see what?
Is our data used to train AI models?
See the evidence on a real document
Send one, sign it, and look at the certificate that comes out.
No credit card required.