SIGNfile
How it worksFeaturesPricingSecurity
Log inStart free
Privacy

Your contracts
aren’t training data.

We don’t read your documents with AI. We don’t summarize them. We don’t train models on them. SignFile uses deterministic verification — the same SHA-256 hash and audit trail the legal industry has trusted for a decade.

Our policy, in one line

We do not use AI to read, summarize, or extract data from customer documents. Verification is performed by a SHA-256 hash. No machine-learning model touches your PDF.

Why AI on documents is a category problem.

The e-signature industry is rapidly adding AI features. Some of these features are useful: search across your archive, automatic field detection when you upload a contract, summarization of what was signed. Some are less obviously useful: extracting clauses to populate templates, training models on signed documents to “learn” what good contracts look like.

For most consumer products this trade-off is fine. For contracts — NDAs, employment agreements, vendor MSAs, settlement letters — it isn’t. A contract is a piece of evidence. Treating it as a corpus for model training risks attorney-client privilege, contractual confidentiality clauses, and GDPR-processor obligations.

What deterministic verification looks like.

SignFile was built around a much older and more boring technology: cryptographic hashes. When a document is completed, we compute a SHA-256 fingerprint of the final PDF and store it alongside the audit trail.

When someone uploads that PDF to signfile.io/verify later — a client, a bank, opposing counsel — we re-hash it. If the hashes match, the document is byte-for-byte identical to what was signed. If even a single byte changed, the hash changes completely and the document shows as tampered.

This is the same approach used by the US Federal Courts’ CM/ECF electronic filing system and by Git for source integrity. It is not new. It is not AI. It is what works.

SignFile approach

  • SHA-256 hash of the final PDF
  • Deterministic — same input, same output
  • Verifiable by anyone with a hash tool
  • Used by federal courts and source-control systems
  • No model training, no inference, no GPU on your contract
  • Document contents are not read or stored as text

AI-on-documents approach

  • Optical character recognition + ML extraction
  • Probabilistic — different runs can produce different output
  • Requires the vendor’s tool to verify
  • Newer, less tested in adversarial contexts
  • Document contents are read, indexed, and may train models
  • Outputs can be challenged as “AI-generated evidence”

Why this distinction matters.

For lawyers: an audit trail backed by a cryptographic hash is admissible. An audit trail backed by an AI summary may not be — opposing counsel can argue the summary isn’t what the document said.

For HR and procurement: employment contracts and vendor MSAs frequently contain confidentiality clauses that prohibit the counterparty from reading the document contents for any purpose other than performing the contract. AI training on those contents may breach those clauses.

For GDPR controllers: if your processor reads document contents with AI, that processing is part of your processor agreement and must be disclosed in your privacy notice. A processor that never reads the contents creates a simpler record of processing.

For everyone: the question isn’t whether AI is good or bad. The question is whether your signature product should be reading your contracts at all. We don’t think it should.

FAQ

AI and data questions,
answered.

Does SignFile use AI on my documents?

No. SignFile does not read document contents with AI, does not summarize or extract data from your contracts, and does not train AI models on uploaded or signed documents. Verification is performed using a deterministic SHA-256 hash of the final PDF, not by reading the document.

Does SignFile offer AI features I can opt into?

No AI features are currently offered on the documents themselves. We may add AI features that operate on your account metadata (for example, a search assistant over your document titles) — these would be opt-in and never read document contents. You would see them clearly labeled if introduced.

What does SignFile do instead of AI to verify a document?

At the moment a document is completed, we compute a SHA-256 cryptographic hash of the final PDF and store it alongside the audit trail (signers, timestamps, IP addresses, user agents). Verification re-hashes the uploaded PDF and compares. This is deterministic — the same input always produces the same output — and is the same approach used by the US Federal Courts’ CM/ECF system and by Git for source integrity.

Can my signers’ data be used for advertising or model training?

No. We do not sell data. We do not train models on customer data. We do not share signer email addresses, IP addresses, or document contents with third parties for advertising.

Where can I read SignFile’s full AI and data policy?

Our privacy policy (/legal/privacy) documents what we collect, why, how long we retain it, and the sub-processors involved. The data-processing addendum (/legal/dpa) is the contractual version of that for business customers.

Sign without
giving up the document.

Free plan, no credit card, three contracts a month to see how it feels. Your PDF never leaves the audit trail.

Start free →
PrivacyTermsSub-processorsCookie policyDo not sell or shareContactRefundImprintDPASecurityStatus