inSigner provides technical tools for creating and recording electronic signature workflows. This notice explains important limits that senders, recipients, and organizations should consider before relying on an electronic signature.
1. Not legal advice
inSigner and Nubesti LLC do not provide legal advice. Website content, product labels, compliance references, templates, audit records, and support communications are general information and technical descriptions, not a legal opinion.
No attorney-client relationship is created by using inSigner. Consult qualified counsel in the relevant jurisdiction when deciding whether an electronic signature is appropriate or whether additional formalities are required.
2. Legal validity varies
Many jurisdictions recognize electronic signatures, but validity and enforceability depend on the applicable law, type of document, parties, intent, consent, attribution, record retention, and signing process.
Some documents may be excluded from general electronic-signature laws or may require a notary, witness, qualified trust service, wet-ink signature, government platform, specific certificate, or other formality. Examples can include wills, family-law documents, powers of attorney, negotiable instruments, certain real-estate documents, regulated notices, or government filings. Exclusions differ by location.
The sender is responsible for determining the law that applies and configuring a suitable workflow. A recipient should seek advice before signing if they do not understand the document or process.
3. Consent, intent, and authority
A valid electronic signature process commonly requires evidence that a person intended to sign and consented to use electronic records. A sender must provide notices and obtain consent where required, and must ensure that each recipient has authority to sign for themselves or an organization.
A signing link should be sent only to the intended recipient. Recipients must not forward a private signing link, reveal an access code or one-time passcode, or allow another person to apply a signature without authority.
4. Identity assurance is configurable
Email delivery alone is not the same as government-issued identity verification. inSigner can support different assurance signals, including email access, access codes, one-time passcodes, phone or WhatsApp delivery, KYC checks, IP and browser information, and account authentication.
No single signal proves identity in every circumstance. Even a successful KYC or OTP result can be affected by compromised devices, shared accounts, inaccurate source data, fraud, provider limitations, or human error. The sender must select controls proportionate to the transaction’s value, sensitivity, legal requirements, and fraud risk.
5. Standards and compliance references
References to ESIGN, UETA, eIDAS, PAdES, RFC 3161, GDPR, AES-256, local electronic-commerce laws, or similar frameworks describe technical capabilities, design objectives, or general context. They do not mean that Nubesti LLC is a regulator, certification body, qualified trust service provider, or legal adviser.
A PAdES level, timestamp, digital seal, or completion certificate describes technical evidence generated or embedded in a document. It does not by itself determine whether a signature is “advanced,” “qualified,” notarized, admissible, or enforceable under a particular law.
Compliance depends on the customer’s full process, including lawful collection, notices, security, authorization, record retention, employee procedures, integrations, and response to data-subject requests.
6. Evidence and verification
inSigner may generate document hashes, timestamps, audit events, signer actions, authentication results, PDF seals, certificates of completion, and public verification records. These features are designed to help explain document integrity and the sequence of events.
Evidence can be challenged, interpreted differently, or given different weight by courts, regulators, experts, and counterparties. Verification confirms only the information the verification process is designed to check; it is not a judgment about the underlying contract, a signer’s legal capacity, or absence of fraud or duress.
Customers should export completed documents and evidence, apply an appropriate retention policy, and maintain any independent records required by law or contract.
7. External trust and identity providers
Customers may select or trigger services from identity providers, communications platforms, timestamp authorities, certificate services, or blockchain timestamp calendars. Those providers operate under their own terms, availability, validation practices, and retention rules.
A third-party provider’s brand or result shown in inSigner does not mean that provider endorses Nubesti LLC, guarantees a legal outcome, or has reviewed the complete signing process. See Subprocessors for current provider categories.
8. Feature availability and security
Features, assurance levels, PAdES levels, timestamps, communications channels, providers, and geographic availability can vary by plan, configuration, certificate, document, deployment, or service status. Planned and “coming soon” capabilities are not commitments.
Security controls reduce risk but cannot eliminate it. No system, identity check, transmission, storage service, cryptographic implementation, or third-party provider is completely immune from failure or attack. Customers and users are responsible for protecting credentials, signing links, devices, API keys, downloaded records, and connected systems.
9. Contact
Questions about this notice or a technical signature record may be sent to hi@insigner.co. We can explain product functionality and available evidence, but we cannot advise whether a document or signature is legally sufficient.