How Do I Prove Who Signed? What an Audit Trail Actually Records

Drop your document here and sign it now. PDF, Word and Excel all work: a .docx or .xlsx is laid out in your browser exactly as it was written, so there is nothing to convert first. Add a signature, a date, a company stamp or a watermark, then download it sealed. Free to start, no account, and the file is never uploaded to do it.

A signature on a page is a claim that a particular person agreed to a particular document. On its own it proves nothing much: handwriting can be copied, an image can be pasted, and a typed name is just a name. What makes a signature defensible is the record around it. That record has a name, an audit trail, and it is worth knowing exactly what is in one, because the parts people assume are in it often are not.

What a signing record actually contains

The document fingerprint. A SHA-256 hash of the exact bytes of the finished file. Change one character, one pixel, one comma, and the hash is completely different. This is what lets anybody confirm that the file they are holding is the file that was signed, rather than a version of it.

The timeline. When the document was sent, when each person opened it, when each one signed, and in what order. This is often the most useful part in a dispute, because arguments about signing are usually arguments about sequence.

The address and device. The IP address each signature came from, and what browser and system was used. Not identity, but corroboration: a signature that arrived from the counterparty’s office network at eleven in the morning is a different proposition from one that arrived from nowhere in particular at three.

The checks that were passed. Whether the signer opened an emailed link, entered a one-time code sent to a phone, entered an access code shared out of band, or presented an ID document. Each is a rung on a ladder, and the record says which rung was used.

What it honestly cannot tell you

It cannot tell you who was holding the device. No electronic method can. A one-time code proves somebody had that phone; an ID check proves somebody presented that document and matched the face on it. Neither is the same as proving a particular human pressed the button, and any product claiming otherwise is overselling.

This matters because the honest version is stronger in practice. A record that says exactly what was observed stands up. A claim that the system "verified the signer" invites the question of how, and a vague answer is worse than a specific limited one.

Choosing how much proof a document needs

Match the check to the consequence. An internal approval, a delivery note or a straightforward supplier agreement is well served by a signing link and a full audit trail. A tenancy, a large purchase or anything where impersonation would actually cost somebody money justifies a one-time code to a phone. Where the amount is significant, or where the parties have never met, an ID check with a liveness step is proportionate.

The mistake to avoid is the same at both ends. Too little proof on something that matters leaves you unable to answer a challenge. Too much on something that does not is friction, and friction is what makes people not sign at all.

What to keep, and for how long

Keep three things together: the signed file, the audit certificate, and a note of what the document was for. The certificate is worth as much as the document when a question comes up a year later, and the two get separated with remarkable ease when one lives in an inbox and the other in a folder.

How long depends on the limitation period for claims under that kind of agreement, plus any tax or sector retention rule that applies to you. Those vary by country and by document type, so check yours rather than taking a general number from an article, and where the document matters, take advice.

The check somebody else can run without you

The strongest position is one where the other party can verify the document themselves. Every document sealed here carries a QR code and a verification page: scan it, or upload the file, and the hash is recomputed and compared to the sealed original. A match means the document is the one that was signed. A mismatch means it is not, and it says so in about two seconds.

That is the part a paper signature has never been able to do. A wet signature on a page tells you somebody wrote on the page. It tells you nothing about whether the pages around it are the ones that were there at the time.

Questions people ask about this

What is a certificate of completion?

The audit certificate issued with a finished document: every signer, the time each one signed, the address it came from, the verification each passed, and the SHA-256 fingerprint of the sealed file. It is what turns a signature into evidence.

How do I verify a signature on a PDF?

Scan the QR code on the page, paste the verification code, or upload the file. The fingerprint is recomputed and compared to the sealed original, and a match means the document is the one that was signed. No account is needed to check.

Can an electronic signature be forged?

Any signature can be forged, on paper or on screen. What differs is what forgery leaves behind: a copied signature image leaves nothing, while a sealed document records the time, the address and a fingerprint of the exact bytes, so a document altered afterwards fails verification.

Is a typed signature legally binding?

It can be. What matters legally is intent rather than the shape of the mark. What a typed name lacks is any evidence of who typed it, which is why the audit trail around it is doing the real work.

Make a signature free →

What PDF Verified is, and what it is not

These checks are a screen, not a verdict. A clean result means nothing was found by the checks that were run, which is not the same as proof that a document is genuine, and a flagged result can have an innocent explanation such as a re-save or a scan. Read the findings rather than the headline, and where a decision carries real consequences, confirm the document with the party that issued it. It is a tool for examining a document, not for producing a forged or altered one.

PDF Verified is a tool for preparing, signing, stamping and checking documents. It is not a law firm, a compliance service or a forensic examiner, and nothing here is legal, financial or compliance advice. Requirements differ by country, by document type and by the party asking, so check what applies to your document before you rely on it, and take advice where the document matters. You are responsible for the documents you create, sign and send, and for having the authority to do so: signing or stamping in somebody else name, or as an organisation you do not represent, is forgery whatever tool is used. To the extent the law allows, we accept no liability for how a document made with this tool is used or relied on. The full position is in our terms of service.

More on esignatures & signing

Tools