← All e-signature guides

E-signature audit trail and certificate of completion

The signature itself is the easy part. What makes it hold up is the record around it — and that record is generated automatically on every document, on every plan.

Free plan available · No credit card required

How it works

  1. 1

    Every action is timestamped as it happens

    Delivered, viewed, signed, declined, voided and completed are each recorded server-side with the originating IP address, not reconstructed afterwards.

  2. 2

    The document is fingerprinted when it is sent

    A SHA-256 hash is taken at the moment of sending. Any later alteration of the original produces a different hash, so the fingerprint on the certificate is checkable.

  3. 3

    The certificate is attached to the signed PDF

    It is not a separate file to keep track of. The signed document and its certificate are one PDF, sent to everyone involved.

What the certificate records

The certificate of completion is a full page appended to the signed document. It carries:

  • Certificate ID and envelope ID
  • When the document was sent and when it completed
  • Whether signing was sequential or all at once
  • Who sent it, with name and email address
  • A SHA-256 fingerprint of the document as sent
  • Each signature image, with the signer’s typed name and email
  • For every signer: the exact time they signed, their IP address and their browser
  • The complete audit trail, event by event, with actor and IP

Why single-recipient links matter here

Each signer receives a private link rather than a shared one. That is what allows the audit trail to attribute a view to a named person instead of recording that an unidentified visitor opened a public URL.

It is a small design decision that determines whether the record is evidence or just a log.

Reading the fingerprint

The SHA-256 hash on the certificate is taken from the document at the moment it was sent for signature. If somebody later produces a version of that contract and claims it is what was signed, hashing their copy and comparing it to the certificate settles the question in seconds.

This is the same mechanism every serious e-signature product uses. It is printed on the certificate rather than buried in a settings page because it is only useful if the person holding the PDF can find it.

Frequently asked questions

What is a certificate of completion?

A record, generated by the signing platform, of how a document was signed: who signed it, when, from where, and what the document looked like at the time. It is the evidence you produce if a signature is ever disputed.

Is the audit trail included on the free plan?

Yes, in full and without a watermark. Holding it back would make a free signature worthless, which would defeat the point of offering one.

Do you record IP addresses of signers?

Yes — the IP address at the moment of each view and each signature, alongside a server-side timestamp. This is standard practice for electronic signatures and is what the certificate is for.

Can the certificate be edited after the fact?

The certificate is generated once, when the final signature lands, and the signed PDF is hashed at that point too. The events it draws on are written as they happen rather than assembled later.

Does this make the signature a qualified electronic signature?

No. This is an advanced electronic signature in eIDAS terms — identity evidenced by a private link, timestamps and IP, rather than by a government-issued certificate. That is sufficient for ordinary commercial contracts; a qualified signature is only required for a narrow set of document types in some countries.

Contracts to send

Free templates you can fill in and send for signature today.

Send your first contract for signature today

Upload a contract you already have, drop the signature fields in, and send it. The free plan includes the full certificate of completion.

Start for free

Free plan available · No credit card required

Related

E-Signature Audit Trail & Certificate of Completion | DraftYourBid