CalmSign Get started
Security

Security you can verify yourself

Every CalmSign document is protected by cryptographic hashing and a complete audit trail. Nothing is hidden.

Cryptographic seal

How we protect every document

1

Document signed

When the signer completes their signature, we capture their identity, device, IP address, and a precise timestamp.

2

Hash generated

A unique SHA-256 fingerprint of the entire document is computed. This hash is mathematically unique to the document's exact contents.

3

Seal applied

The hash, signature, and metadata are embedded in the document. Both parties receive an identical, sealed copy.

Screenshot: Seal process — document to cryptographic hash
Tamper detection

Any change breaks the seal

SHA-256 produces a completely different hash if even a single bit of the document is changed. There's no way to alter a CalmSign document without the tampering being detected.

Original
sha256:9f86d081884c7d659a2feaa0c55ad015
Modified (even one character)
sha256:60303ae22b998861bce3b28f33eec1be
Screenshot: Tampered vs verified comparison
Audit trail

Every action is recorded

CalmSign logs the full lifecycle of every document: creation, delivery, viewing, signing, and verification. Each event includes a timestamp, IP address, and device information.

Precise timestamps
Down to the second, in UTC
Signer identity
Name, email, IP, and device fingerprint
Exportable certificate
Download a standalone audit report for legal use
Screenshot: Full audit trail for a document
Public verification

Anyone can verify a document

You don't need a CalmSign account to verify a signed document. Upload the file and we'll confirm whether it's authentic, who signed it, and when — in seconds.

Try the verifier
Screenshot: Public verification page

Our data practices

Encrypted in transit & at rest

All data is encrypted using TLS 1.3 in transit and AES-256 at rest. Documents are stored in geographically distributed, SOC 2 compliant infrastructure.

No third-party tracking

We don't embed third-party analytics or tracking scripts in the signing experience. Your signers' data stays between you and them.

GDPR compliant

CalmSign is designed with privacy by default. We collect only what's needed for the signature process and nothing more.

Your documents, your control

Delete your documents anytime. When you delete, we remove the document from our systems entirely — no residual copies.

Start signing securely

Every document is tamper-proof from day one. Free to start.

Create free account