Skip to main content
DocsAutomator’s e-signature solution provides electronic signatures that the US, EU and UK recognise, for documents that need no special form. Signing and acceptance produce simple electronic signatures. They are valid for documents that need no special form. Some documents need a notary, a witness, handwritten ink or a qualified electronic signature, and neither covers them. Do not use signing or acceptance for disclosures that a US law requires you to give a consumer in writing: ESIGN (15 U.S.C. 7001(c)) asks for a separate consumer consent that these flows do not collect. This is not legal advice.

United States

ESIGN Act

The Electronic Signatures in Global and National Commerce Act says a signature, contract or record may not be denied legal effect only because it is electronic. It applies to documents that need no special form. Key Requirements:
  • Parties must demonstrate intent to sign
  • Consent to conduct business electronically
  • Association of the signature with the record
  • Record retention and reproducibility
DocsAutomator Compliance:
  • Signers receive unique secure links via email and actively complete signature fields
  • Accessing the signing portal demonstrates electronic consent
  • Each signature embeds into the PDF with complete audit trails
  • All documents and logs are securely stored indefinitely

UETA

The Uniform Electronic Transactions Act provides consistent rules across 49 U.S. states. Key Requirements:
  • Records must be attributable to a person
  • Records must be capable of retention
  • Parties must obtain copies
DocsAutomator Compliance:
  • Every signature links to the signer via email, IP address, browser information, and timestamp
  • Documents store securely with no automatic deletion
  • Signers and owners receive completed PDFs via email and dashboard access

European Union

eIDAS (Simple Electronic Signatures)

eIDAS establishes legal frameworks for electronic signatures across EU member states. DocsAutomator provides Simple Electronic Signatures (SES). SES Compliance:
  • Signatures capture digitally and embed into PDFs
  • Each signer accesses unique signing sessions via secure, time-limited tokens
  • All actions record with server timestamps in audit trails
  • Original and signed document hashes (SHA-256) are stored, and the signed PDF is digitally sealed and timestamped to detect tampering

GDPR

The General Data Protection Regulation governs personal data collection, processing, and storage for EU residents. DocsAutomator Compliance:
  • Personal data processed based on contractual necessity
  • Only essential information collected: email, name, signature, audit data
  • Document owners can delete sessions and associated data upon request
  • Data encrypted in transit (TLS) and at rest via cloud infrastructure
  • Signer data is not sold or shared with third parties for marketing

Security Measures

Audit Trail

Every e-signature session maintains a tamper-evident audit trail recording:
  • Session creation and document generation
  • Email invitation delivery timestamps
  • Signer access to signing links
  • IP address and browser information per action
  • Individual field completion timestamps
  • Session completion and PDF finalization

Document Integrity

  • SHA-256 Hashing: Cryptographic hashes of the original document and of the final signed PDF are stored and returned by the audit endpoint
  • Digital Seal: The final signed PDF carries a digital signature from DocsAutomator. Any change to the file after signing shows as “document has been modified” in Adobe Acrobat and other PDF validators
  • Trusted Timestamp: The seal embeds an RFC 3161 timestamp from an independent timestamp authority (DigiCert), so the signing time does not depend on our server clock
  • Certificate of Completion: Automatically generated page showing all signers, signatures, and completion timestamps
The seal uses a certificate issued by DocsAutomator. Adobe Acrobat shows the signature as valid but lists the certificate issuer as unknown, because it is not on the Adobe Approved Trust List. The tamper evidence and the timestamp are not affected by this.

Access Control

  • Secure Tokens: Each signer receives unique 256-bit cryptographically random access tokens
  • Time-Limited Access: Signing links expire after configurable periods (default: 30 days)
  • Rate Limiting: Protection against brute force attacks

Infrastructure Security

  • Encryption in Transit: All communications secured via TLS/HTTPS
  • Cloud Storage: Documents on Google Cloud infrastructure with enterprise-grade security
  • Database Security: MongoDB Atlas with encryption at rest and network isolation

Certificate of Completion

Every signed document automatically includes a Certificate of Completion page containing:
  • Document title and completion timestamp
  • List of all signers with names and email addresses
  • Visual reproduction of each signature
  • Unique session identifier for audit reference

FAQ

Yes, for documents that need no special form. In the United States, the ESIGN Act and UETA say a signature may not be denied legal effect only because it is electronic. In the EU, the eIDAS regulation says the same for a simple electronic signature; only a qualified electronic signature has the same standing as a handwritten one. Where the law requires a special form, neither signing nor acceptance is enough. This is not legal advice.
DocsAutomator provides simple electronic signatures. Some documents may require Advanced or Qualified Electronic Signatures, wet ink signatures, or notarization. Consult a legal professional regarding your specific use case.
Signed documents and audit trails retain indefinitely unless deleted from your workspace.
Yes. Each signed document includes a Certificate of Completion, and the original document hash stores in the system for integrity verification.
Last modified on September 22, 2026