SIGNfile
How it worksFeaturesPricingSecurity
Log inStart free
Audit certificate

Every signature comes
with the evidence.

Every completed SignFile document generates an audit certificate — a tamper-evident record of what happened, when, from where, and on which device. Downloadable from the document page. Admissible as evidence under the ESIGN Act.

Audit certificate
Service Agreement
● Completed
Document
Service Agreement — Acme × Beaumont Co.
2 pages · 48 KB · completed Jan 12, 2026 at 09:44 UTC
Signers
Alex Morgan (Owner) — Jan 12, 09:42 UTC
Jordan Blake — Jan 12, 09:44 UTC
Signature events
Created by Alex Morgan
Jan 12, 09:42 UTC · 82.14.63.9 · Chrome 121 / macOS
Opened by Jordan Blake
Jan 12, 09:43 UTC · 198.51.100.7 · Safari 17 / iOS
Signed by Jordan Blake
Jan 12, 09:44 UTC · 198.51.100.7 · Safari 17 / iOS
Completed — all parties signed
Jan 12, 09:44 UTC
SHA-256 hash
a3f91c4e8b2d7f6091c2eda053ba98773d2e4f8a1b6c9d0e2f3a4b5c6d7e8f901
Sample certificate · real format on every documentVerify this document →

What’s in it.

  • Document metadata
    Title, page count, file size, completion timestamp.
  • Signer identities
    Name, email, role (Owner / signer), and order of signing.
  • Timestamps
    For every event: created, sent, opened, viewed, signed, completed.
  • IP addresses
    The IP address of the device each signer used to view and sign.
  • User agents
    Browser and OS used to sign (e.g., Safari 17 / iOS).
  • SHA-256 hash
    Cryptographic fingerprint of the final PDF. Modifies if any byte changes.
Why it matters

Built for the day someone challenges the signature.

Dispute resolution

When a counterparty claims they didn’t sign — or claims the document changed after signing — the certificate gives you the specific signer, device, IP, and timestamp. The hash proves whether the PDF was modified.

Internal compliance

Procurement, legal, and HR teams typically need evidence that a contract was reviewed and signed by the right party. SignFile’s certificate gives auditors the data they ask for without forcing you to maintain a separate system.

Court admissibility

The ESIGN Act (15 U.S.C. § 7001) and UETA grant electronic signatures the same legal weight as wet ink. The certificate gives you the evidentiary record courts typically require to admit an electronic signature record.

How to access the certificate.

From any completed document in your dashboard, open the document and click Download certificate. The certificate is a signed PDF that you can attach to a contract file, email to opposing counsel, or print and keep with the original.

The full certificate (including signer emails, IPs, and user agents) is only available to the workspace owner. The public verification page at signfile.io/verify shows a privacy-preserving subset: document title, signer names, signing timestamps, and the SHA-256 hash. This is the version you share with third parties.

FAQ

Certificate questions,
answered.

What is an audit certificate?

An audit certificate is a record of every event that happened to a document: when it was created, when it was sent, when each signer opened and signed it, the IP address and user agent of the device used to sign, and a SHA-256 hash of the final PDF. On SignFile, every completed document generates one automatically and you can download it from the document page.

Is the SignFile audit certificate court-admissible?

SignFile records the data points courts typically require to admit an electronic signature record under the ESIGN Act (15 U.S.C. § 7001) and UETA: signer identity, intent, signature event, timestamp, and a tamper-evident hash. Whether a certificate is admitted in any specific case depends on the facts of that case and the court’s discretion. We can provide the certificate as a PDF and the underlying event log as JSON for forensic review.

What’s the difference between the audit certificate and the public verify page?

The public verify page (/verify) is intentionally limited: it shows the document’s title, the signers’ names, and the SHA-256 hash. It does not show emails, IP addresses, or user agents — that information is signer PII. The full audit certificate includes the PII and is only available to the workspace owner.

How long is the audit trail retained?

Audit events are retained for the lifetime of the workspace. If you cancel your subscription, your signed documents and audit certificates remain accessible read-only. We never delete audit events from completed documents.

Can the certificate detect if a PDF was modified after signing?

Yes. The SHA-256 hash in the certificate is computed at the moment of completion. If a single byte of the PDF changes after signing, the hash changes completely and the document shows as tampered on /verify. This is the same property that makes the certificate useful as evidence.

Sign with
receipts.

Free plan, no credit card. Three contracts a month to see what every completed document looks like.

Start free →
PrivacyTermsSub-processorsCookie policyDo not sell or shareContactRefundImprintDPASecurityStatus