Signing and acceptance produce simple electronic signatures. They are valid for documents that need no special form. Some documents need a notary, a witness, handwritten ink or a qualified electronic signature, and neither covers them. Do not use signing or acceptance for disclosures that a US law requires you to give a consumer in writing: ESIGN (15 U.S.C. 7001(c)) asks for a separate consumer consent that these flows do not collect. This is not legal advice.
United States
ESIGN Act
The Electronic Signatures in Global and National Commerce Act says a signature, contract or record may not be denied legal effect only because it is electronic. It applies to documents that need no special form. Key Requirements:- Parties must demonstrate intent to sign
- Consent to conduct business electronically
- Association of the signature with the record
- Record retention and reproducibility
- Signers receive unique secure links via email and actively complete signature fields
- Accessing the signing portal demonstrates electronic consent
- Each signature embeds into the PDF with complete audit trails
- All documents and logs are securely stored indefinitely
UETA
The Uniform Electronic Transactions Act provides consistent rules across 49 U.S. states. Key Requirements:- Records must be attributable to a person
- Records must be capable of retention
- Parties must obtain copies
- Every signature links to the signer via email, IP address, browser information, and timestamp
- Documents store securely with no automatic deletion
- Signers and owners receive completed PDFs via email and dashboard access
European Union
eIDAS (Simple Electronic Signatures)
eIDAS establishes legal frameworks for electronic signatures across EU member states. DocsAutomator provides Simple Electronic Signatures (SES).
SES Compliance:
- Signatures capture digitally and embed into PDFs
- Each signer accesses unique signing sessions via secure, time-limited tokens
- All actions record with server timestamps in audit trails
- Original and signed document hashes (SHA-256) are stored, and the signed PDF is digitally sealed and timestamped to detect tampering
GDPR
The General Data Protection Regulation governs personal data collection, processing, and storage for EU residents. DocsAutomator Compliance:- Personal data processed based on contractual necessity
- Only essential information collected: email, name, signature, audit data
- Document owners can delete sessions and associated data upon request
- Data encrypted in transit (TLS) and at rest via cloud infrastructure
- Signer data is not sold or shared with third parties for marketing
Security Measures
Audit Trail
Every e-signature session maintains a tamper-evident audit trail recording:- Session creation and document generation
- Email invitation delivery timestamps
- Signer access to signing links
- IP address and browser information per action
- Individual field completion timestamps
- Session completion and PDF finalization
Document Integrity
- SHA-256 Hashing: Cryptographic hashes of the original document and of the final signed PDF are stored and returned by the audit endpoint
- Digital Seal: The final signed PDF carries a digital signature from DocsAutomator. Any change to the file after signing shows as “document has been modified” in Adobe Acrobat and other PDF validators
- Trusted Timestamp: The seal embeds an RFC 3161 timestamp from an independent timestamp authority (DigiCert), so the signing time does not depend on our server clock
- Certificate of Completion: Automatically generated page showing all signers, signatures, and completion timestamps
The seal uses a certificate issued by DocsAutomator. Adobe Acrobat shows the signature as valid but lists the certificate issuer as unknown, because it is not on the Adobe Approved Trust List. The tamper evidence and the timestamp are not affected by this.
Access Control
- Secure Tokens: Each signer receives unique 256-bit cryptographically random access tokens
- Time-Limited Access: Signing links expire after configurable periods (default: 30 days)
- Rate Limiting: Protection against brute force attacks
Infrastructure Security
- Encryption in Transit: All communications secured via TLS/HTTPS
- Cloud Storage: Documents on Google Cloud infrastructure with enterprise-grade security
- Database Security: MongoDB Atlas with encryption at rest and network isolation
Certificate of Completion
Every signed document automatically includes a Certificate of Completion page containing:- Document title and completion timestamp
- List of all signers with names and email addresses
- Visual reproduction of each signature
- Unique session identifier for audit reference
FAQ
Are electronic signatures legally binding?
Are electronic signatures legally binding?
Yes, for documents that need no special form. In the United States, the ESIGN Act and UETA say a signature may not be denied legal effect only because it is electronic. In the EU, the eIDAS regulation says the same for a simple electronic signature; only a qualified electronic signature has the same standing as a handwritten one. Where the law requires a special form, neither signing nor acceptance is enough. This is not legal advice.
What documents cannot be signed electronically with DocsAutomator?
What documents cannot be signed electronically with DocsAutomator?
DocsAutomator provides simple electronic signatures. Some documents may require Advanced or Qualified Electronic Signatures, wet ink signatures, or notarization. Consult a legal professional regarding your specific use case.
How long are signed documents stored?
How long are signed documents stored?
Signed documents and audit trails retain indefinitely unless deleted from your workspace.
Can I verify a document's authenticity?
Can I verify a document's authenticity?
Yes. Each signed document includes a Certificate of Completion, and the original document hash stores in the system for integrity verification.