Skip to the content

Trust

Signature standards

What is inside a signed PDF, and how anyone can check it.

The record of each signature

Every signature is a row in an append-only record: who (the seat), when, the wording agreed to, the address and browser, and a hash that includes the row before it, so a change anywhere breaks the chain.

The seal

When the last person signs, the finished PDF gets a digital signature over the whole file (a detached PKCS#7 signature in the PDF itself). Any change after sealing makes the signature fail in a PDF reader. By default the seal comes from a certificate Docustay makes for the deployment, so a reader may say the signer is unverified; a certificate from a trusted authority can be used instead (self-hosters set their own).

The trusted timestamp

The seal is stamped by a time-stamping authority (RFC 3161), so the time it was sealed is vouched for by someone other than us. If the authority cannot be reached the document is still sealed and the certificate page says it was not timestamped.

The certificate page

Every signed copy ends with a Certificate of Completion: each person, the time and address of each act, the document's fingerprint (SHA-256) and the audit trail, printed on the PDF itself.

Checking a copy

Anyone can drop a signed PDF on the Verify page, which reads the seal and the fingerprint from the file itself and says whether it is intact. It needs no account.

What this is, and is not

This is a simple electronic signature with a strong evidence record and a tamper-evident seal. It is not a qualified electronic signature and does not check anyone's identity beyond their email address or an access code you share. See Legal validity.

A worked example: checking a copy

A landlord is sent a signed lease addendum by email. They drop the PDF on the Verify page. It reads the seal and the document's fingerprint from the file itself, and says the file is intact, who signed and when. They change one word in a copy and drop that: the page says the file has been altered.

Opening the seal in a PDF reader

A reader shows the digital signature panel. Because the default certificate is made for the deployment rather than bought from a trusted authority, a reader may say the signer's identity is unknown. The seal still proves the file has not changed since it was sealed; a workspace that needs the reader's green tick can use a certificate from a trusted authority.

The fingerprint

The fingerprint is a SHA-256 of the content of the document as signed. It appears on the certificate page and in the API, so you can store it and compare later.

Where this stops

A simple electronic signature with a seal and a trusted timestamp is not a qualified signature and is not issued by a regulated trust provider. If you need one, Docustay is not the right tool.

Keep reading