Evidence and verification

Audit Trails and Completion Certificates

The audit trail records what happened during signing. The completion certificate seals that record with cryptographic hashes so that later modification can be detected. Together they are what makes a signed document defensible.

Free · No credit card · No signing limits

Short answer

An e-signature audit trail is a timestamped log of every meaningful event in a signing workflow: when the request was sent, when each recipient opened it, what they completed, and when they submitted. A completion certificate is the sealed summary issued when the workflow finishes, containing SHA-256 hashes computed over the document and the captured signing information. Because any change to the underlying document produces a different hash, comparing the stored hash against a recomputed one reveals whether anything was altered after signing. Bond4Docs issues a completion certificate with a public identifier that can be checked without an account.

Every event, timestamped

Sent, viewed, completed, and submitted events recorded with time and IP information.

Hash-based tamper evidence

SHA-256 hashes over the document and signing information make later edits detectable.

Independently checkable

A public certificate identifier lets a counterparty verify the record without an account.

What the audit trail records

An audit trail is only useful if it captures the events someone would actually ask about. The questions that arise in a dispute are consistent: was it really sent to that address, did that person open it, what did they see, what did they enter, and when.

  • When the request was created and sent, and to which address
  • When each recipient first opened the document
  • Which fields each recipient completed
  • When each recipient submitted their portion
  • IP information associated with signing activity
  • Timestamps for every recorded event

What a completion certificate adds

The audit trail describes the process; the certificate seals the result. When a workflow completes, Bond4Docs computes SHA-256 hashes over the document and over the captured signature information, and stores them with the certificate record.

Verification recomputes those hashes from the stored document and compares them with the values recorded at completion. If they match, the document is byte-for-byte what was signed. If they differ, something changed after the fact. This is what "tamper-evident" means in practice: it does not prevent modification, it makes modification detectable.

What it does not do

A completion certificate is evidence about a document and a process. It is not notarization, it is not government identity verification, and it does not prove that the person behind an email address is who they claimed to be. Those are separate controls with separate requirements.

It also does not make an otherwise unenforceable agreement enforceable. If a document falls into an ESIGN exclusion, or the underlying contract fails for ordinary reasons, no amount of signing evidence changes that.

Retention is your responsibility too

ESIGN and UETA both contemplate that parties can accurately reproduce the record later. Download completed documents and their certificates and retain them according to whatever schedule applies to your business. Keeping the file only inside one vendor's account is a single point of failure for records you may need years from now.

Direct answers

Frequently asked questions

What is a certificate of completion?

It is the record issued when every recipient has finished signing. It summarizes the signing events and includes hash values computed over the document and the captured signature information, so later changes to the file can be detected.

How do I verify a signed Bond4Docs document?

Each completion certificate carries a public identifier. Entering that identifier on the Bond4Docs verification page returns the stored certificate record so the document and its hashes can be checked.

Does an audit trail prove who signed?

It provides evidence of attribution — the address the request went to, the time it was opened, and the IP information recorded — but it is not identity verification. For transactions requiring proof of identity, additional controls such as notarization or identity proofing are needed.

Can the audit trail be edited?

Signing events are recorded as they occur and the completion certificate hashes cover the captured information, so altering the record after completion would cause verification to fail.

Last reviewed .

No credit card required

Send your first document for free

Upload a PDF, add recipients, place fields, and start collecting electronic signatures without signing limits.

Create a free account