BlogSecurity

Inside a tamper-evident audit trail

The trail is the completion record plus the PDF. It is useful when someone later asks whether the file changed.

The hash belongs to the final file, not to a marketing claim.inSigner

A tamper-evident record does not freeze the world. It gives you a way to notice that a file is no longer the file that was signed. inSigner puts a SHA-256 hash of the final file in the completion record.


01 · What the record contains

What the record contains

The completion record follows the signed PDF. It includes a SHA-256 hash of that final file. Compare a later copy with the hash. If they differ, the copy is not the file that was completed. The hash is an integrity check. It is not encryption, and it is not a certificate that a person is who they claim to be.

02 · What the product stores

What the product stores

The workspace keeps the completed PDF and the completion record. Download both. Email delivery and reminders are included. The workspace does not replace your own archive, and it does not promise a retention period beyond what the product documents today.

The useful question is not whether a trail sounds strong. It is whether you can still open the file that the hash names.

03 · Who can rely on it

Who can rely on it

Your team can use the record to see whether a file still matches. A court, a customer, or a regulator decides what weight to give it. This guide does not say a court must accept the record by itself. The words in the PDF, and the law that governs them, do that work if the law gives them that effect.

  • Did we download the completed PDF?
  • Did we download the completion record?
  • Does the record show a SHA-256 hash of that file?
  • Are both stored in the same matter file?

04 · What not to add

What not to add

Do not describe the hash as encryption. Do not say a file is covered by a certification program the company has not stated. The security overview is the place for the controls the service actually describes.

05 · A simple check

A simple check

After completion, download the PDF and the record. Store them together. If someone sends you a PDF months later, hash that file and compare it with the record. A match supports integrity. A mismatch means you are looking at a different file.

Primary sources

inSigner security overview
in

Written by

inSignerGuides from the inSigner team. They describe the product and name public laws. They are not legal advice.

The inSigner brief

Get the next guide by email.

One note when a new guide is published.

Subscribe