A certificate of completion is the part of an electronic signature that does the work in a dispute. Here is what belongs in one, how to read it, and what a document fingerprint is for.
Nobody reads the certificate of completion. It arrives stapled to the back of a signed PDF, full of timestamps and hexadecimal, and gets filed without a glance.
Which is fine, right up until the moment somebody says "I never agreed to that." At that point the certificate stops being paperwork and becomes the only thing standing between you and an argument you cannot win.
An electronic signature has two parts that are easy to conflate. There is the act — the signer drawing or typing their name and clicking a button. And there is the record of that act.
The act, on its own, is nearly worthless as proof. An image of a signature can be copied off any previously signed document. What makes the act evidential is the record: a contemporaneous, tamper-evident account of who did what, when, and from where.
That record is the audit trail, and the certificate of completion is how it is presented.
A certificate worth having carries at least the following:
If a certificate is missing IP addresses or the document hash, it is a receipt rather than evidence.
A SHA-256 hash is a short string derived from a file's contents. Change a single character anywhere in the document and the hash changes completely. It is also one-way: you cannot reconstruct the document from the hash.
The hash is taken at the moment the document is sent for signature and printed on the certificate. That gives you something quietly powerful. If a counterparty ever produces a version of the contract and says "this is what I signed", you hash their copy and compare. Identical hash, same document. Different hash, different document, and the conversation is over in about thirty seconds.
This is why the hash belongs printed on the certificate rather than stored in a settings page somewhere. Evidence you cannot find is not evidence.
There is a design decision underneath all this that determines whether the audit trail is worth anything: whether each signer gets their own link, or whether everyone shares one.
With a shared link, the trail can only honestly say that somebody opened the document from a given IP. With a private, single-recipient link, it can say that the link sent to a named person at a named address was opened at a given time from a given IP.
That is the difference between a log and an attribution. Any platform doing this properly issues per-recipient links; it is worth checking that yours does.
The usual mental model is that paper is the safe option and electronic is the risky modern thing. On evidence, the ranking is generally the other way round.
A printed, signed and scanned contract gives you: an image of a signature, a date somebody wrote by hand, and no reliable way to show that page three was not replaced before scanning. There is no timestamp you can trust, no IP, no record of when it was received or read, and no fingerprint.
A properly recorded electronic signature gives you all of those. It is not that paper is worthless — a signed contract is a signed contract — but the idea that it is the more defensible option does not survive contact with the details.
One practical habit worth forming: make sure the signed document and its certificate are a single PDF, not two files.
Two files means one of them eventually goes missing, usually the one you need, usually two years later when the person who filed it has left. A certificate appended to the signed document travels with it through every email, every folder migration and every handover.
That is how we do it, on every plan including the free one — holding an audit trail back from a free tier would make the signatures on that tier close to worthless, which rather defeats the point of offering it.
Here is a fair way to judge any e-signature tool. Send yourself a document, sign it, and open the certificate.
Can you tell who signed, exactly when, from which IP, and whether the document has changed since? If yes, you have evidence. If it is a page with a logo and a date on it, you have a receipt — and you will find out which one it was at the worst possible moment.
DraftYourBid learns from your winning proposals and generates tailored bids in minutes — in your voice, not a template.
Create your free account →