Signature Integrity at SignVerse

Last updated: July 3, 2026 · Document version 1.0

Why a document signed on SignVerse can be trusted — and defended.

1.What "integrity" means for an e-signature

A signature is only as strong as the evidence behind it. For a signed document to hold up — in an internal dispute, a customer disagreement, or a courtroom — you need to be able to show four things:

SignVerse is engineered so that each of these has independent, verifiable evidence.

2.Verified signing ceremonies

Every step — viewed, started, verified, signed, declined, delegated — is written to the audit trail as it happens.

3.The tamper-evidence chain

At every material stage of a document's life — original upload, fields locked for signing, each individual signer's completion, any revision or amendment, and final completion — SignVerse computes a cryptographic snapshot (SHA-256) covering:

That last element is what makes the record a chain: every snapshot is mathematically bound to everything that came before it. Change any value, signature, or ordering after the fact — even one byte — and the chain no longer verifies. SignVerse can re-derive and verify the entire chain on demand, and the chain's head hash travels with the document.

4.Cryptographic seals

SignVerse also supports embedded PAdES-LTV sealing (long-term validation inside the PDF itself, with the certificate chain, OCSP/CRL responses, and timestamp embedded in the Document Security Store) alongside the detached platform seal. The detached seal remains — it binds the tamper-evidence chain, which PAdES itself does not know about — so both witnesses are always available.

5.Signature forensics

SignVerse goes beyond "a box was drawn" — every captured signature is analyzed by a deterministic forensic engine:

Each check contributes a fixed, published-in-code penalty weight to a 0–100 score — there is no machine-learning black box, so every score can be explained, reproduced, and defended. Scores band into Highly Authenticated, Compliance Warning, and Forensic Fraud Alert; a fraud-alert score automatically quarantines the envelope.

6.Quarantine: humans decide, auditably

A quarantined envelope cannot quietly proceed. It enters a review workflow where an authorized reviewer (permission-gated) examines the forensic evidence and decides: approve, reject, or require re-signing. The decision, the reviewer's identity, and the forensic context are permanently recorded. The forensic ledger itself is append-only — one immutable row per signature, including the full penalty detail.

7.An audit trail that can't be edited

The audit trail is append-only by construction: application code contains no path that updates or deletes an audit record. It captures the envelope lifecycle, every ceremony step, verification events (never the codes themselves), seal creation, quarantine decisions, and administrative actions — each with a timestamp and the true actor (a person's email, an API client's ID — never one masquerading as the other). Personal data inside audit details is masked.

8.Signing links that behave like evidence

9.The evidence pack, end to end

For any completed document, SignVerse can produce: the sealed document, the verified tamper-evidence chain, the full ceremony audit trail, per-signature forensic scores with their explanations, and the seal's key identity and any third-party attestation. Together these support the core requirements of electronic-signature frameworks such as ESIGN/UETA and the principles of eIDAS advanced signatures — the signature is uniquely linked to the signer, capable of identifying them, and bound to the document such that any subsequent change is detectable.

SignVerse documents these properties as engineering facts; whether a given ceremony meets a specific legal standard in a specific jurisdiction depends on how you configure verification, and should be confirmed with your counsel.