BlogSecurity
Inside a tamper-evident audit trail
The trail is the completion record plus the PDF. It is useful when someone later asks whether the file changed.
The hash belongs to the final file, not to a marketing claim.inSigner
A tamper-evident record does not freeze the world. It gives you a way to notice that a file is no longer the file that was signed. inSigner puts a SHA-256 hash of the final file in the completion record.
01 · What the record contains
What the record contains
The completion record follows the signed PDF. It includes a SHA-256 hash of that final file. Compare a later copy with the hash. If they differ, the copy is not the file that was completed. The hash is an integrity check. It is not encryption, and it is not a certificate that a person is who they claim to be.
02 · What the product stores
What the product stores
The workspace keeps the completed PDF and the completion record. Download both. Email delivery and reminders are included. The workspace does not replace your own archive, and it does not promise a retention period beyond what the product documents today.
The useful question is not whether a trail sounds strong. It is whether you can still open the file that the hash names.
03 · Who can rely on it
Who can rely on it
Your team can use the record to see whether a file still matches. A court, a customer, or a regulator decides what weight to give it. This guide does not say a court must accept the record by itself. The words in the PDF, and the law that governs them, do that work if the law gives them that effect.
- ✓Did we download the completed PDF?
- ✓Did we download the completion record?
- ✓Does the record show a SHA-256 hash of that file?
- ✓Are both stored in the same matter file?
04 · What not to add
What not to add
Do not describe the hash as encryption. Do not say a file is covered by a certification program the company has not stated. The security overview is the place for the controls the service actually describes.
05 · A simple check
A simple check
After completion, download the PDF and the record. Store them together. If someone sends you a PDF months later, hash that file and compare it with the record. A match supports integrity. A mismatch means you are looking at a different file.
Primary sources
inSigner security overview






