Security you can verify yourself
Every CalmSign document is protected by cryptographic hashing and a complete audit trail. Nothing is hidden.
How we protect every document
Document signed
When the signer completes their signature, we capture their identity, device, IP address, and a precise timestamp.
Hash generated
A unique SHA-256 fingerprint of the entire document is computed. This hash is mathematically unique to the document's exact contents.
Seal applied
The hash, signature, and metadata are embedded in the document. Both parties receive an identical, sealed copy.
What the seal actually covers
When the last signer finishes, CalmSign freezes an immutable snapshot of the agreement: the final rendered document, every completed field value, and the signature marks themselves. SHA-256 runs over that snapshot and returns a 256-bit digest, written as the 64 hexadecimal characters you see on the verification screen. The digest is not a copy of the document and cannot be turned back into one — it is a fingerprint, small enough to print on a certificate and specific enough that no other document shares it.
That digest, the signature data, and the audit metadata are then embedded in the signed copy itself. Both parties receive the same sealed file, so neither side has to trust the other's version — or ours. If the two copies ever disagree, the digest says which one moved.
It is worth being precise about what the seal does and does not do. It does not stop someone printing the document and editing the printout, and it does not encrypt the contents against the people you sent them to. What it does is make undetected alteration impossible: any change to a sealed document is arithmetic, and the arithmetic no longer adds up.
Any change breaks the seal
SHA-256 produces a completely different hash if even a single bit of the document is changed. There's no way to alter a CalmSign document without the tampering being detected.
The two hashes below differ by one character in the underlying document. Not one paragraph — one character. This is the avalanche property of a cryptographic hash: flip a single bit of input and roughly half the output bits change, with no resemblance between the before and after. There is no way to nudge a digest gently in the direction you want, and no known way to construct a second document that happens to produce the same one.
Re-saving the file through an editor, adding a page, correcting a date, or swapping a signature image all count as changes. That is the point: the seal cannot tell an innocent edit from a dishonest one, so it refuses to bless either.
Every action is recorded
CalmSign logs the full lifecycle of every document: creation, delivery, viewing, signing, and verification. Each event includes a timestamp, IP address, and device information.
The seal proves a document has not changed. The audit trail is what proves the story around it — that this person, at this address, on this device, opened this document at this minute and signed it four minutes later. In a dispute, that sequence is usually what settles the question, because the argument is rarely about the text. It is about whether the signature happened the way one side says it did.
Tamper detection built in
Every signed document carries a SHA-256 seal over an immutable snapshot. CalmSign verifies that seal automatically and surfaces any tampering — backed by a full audit trail of who signed, when, from which IP and device.
The check runs on every open, not on request, so a broken seal announces itself rather than waiting to be discovered. Because the digest and the snapshot it covers both travel inside the signed copy, the same check can be repeated by anyone holding the file — the proof is self-contained rather than a lookup against a database we control.
How a recipient checks a document
A proof only counts if the other side can run it. Verification needs no CalmSign account, no login, and no cooperation from whoever sent the document — which is the whole point, since the person most likely to want to check a contract is the person who did not create it.
Open the sealed copy or the signing link
Every party to the agreement is sent the same sealed copy when signing completes, and the original signing link keeps working afterwards. Either one is enough to start a check.
Compare the recomputed digest against the seal
SHA-256 is recomputed over the snapshot and compared, character for character, with the digest recorded at signing. Identical means the document is byte-for-byte what was signed. Different means something moved, and the result says so in those words rather than hedging.
Download the audit certificate
The certificate is a standalone document listing every recorded event with its UTC timestamp, IP address, and device, alongside the sealed digest. It is the artefact you attach to a filing or hand to a lawyer, and it stands on its own without a link back to us.
ESIGN, eIDAS, and what actually matters in a dispute
Electronic signatures are legally binding in most jurisdictions under laws like ESIGN in the United States, eIDAS in the European Union, and equivalent legislation elsewhere. Both frameworks work by refusing to discriminate: a signature is not denied legal effect merely because it is electronic. Neither framework hands out a stamp that makes a signature valid. What they do is set out the conditions under which an electronic record carries the same weight as ink.
Those conditions are practical rather than technical. The signer has to have intended to sign. They have to have agreed to transact electronically. The signature has to be attributable to them and associated with the record it belongs to. And the record has to be retained in a form that can be accurately reproduced later. CalmSign is built around that last group of requirements: the signing flow records intent and consent as events, the audit trail attributes the signature to a named person at a specific address and moment, and the seal is what proves the record being reproduced today is the record that was signed.
In practice, disputes almost never turn on whether electronic signatures are allowed. They turn on evidence — whether you can show who signed, when, and that the document has not changed since. That is the question this page is about, and it is the question the seal and the audit trail are designed to answer without argument.
This is a description of how the product works, not legal advice. Some categories of document — wills, certain family and property instruments, and specific regulated filings — are excluded from electronic signing in some jurisdictions. If a particular agreement matters, check the rules that apply to it.
Our data practices
Encrypted in transit & at rest
Data is encrypted in transit and at rest using industry-standard TLS and AES-256, so documents stay protected on the wire and in storage.
No third-party tracking
We don't embed third-party analytics or tracking scripts in the signing experience. Your signers' data stays between you and them.
Privacy by default
CalmSign is designed with privacy by default. We collect only what's needed for the signature process and nothing more.
Your documents, your control
Delete your documents anytime. When you delete, we remove the document from our systems entirely — no residual copies.
Retention and deletion
Documents stay for as long as you want them and no longer. There is no expiry timer and no archival tier that quietly moves your agreements somewhere you cannot reach them. Deletion is yours to trigger, and when you trigger it the document is removed rather than hidden behind a flag — which also means it is genuinely gone, so download anything you need first.
Because the seal is self-contained, deleting your copy does not invalidate anyone else's. A signed copy already downloaded by you or by a signer keeps its digest, its embedded audit data, and its ability to be verified. The proof lives in the document, not in your subscription — which is deliberate, and is the same reason a cancelled account never turns a signed agreement into an unverifiable one.
The minimum we can collect to make a signature defensible is the signer's name and email, the addresses and devices involved, and the timing of each event. That is what the audit trail is made of, so it is not optional — but it is also the whole list. We do not build behavioural profiles from it and we do not sell it. See what each plan includes for how this applies across Free, Pro, and Business: security is identical on all three.
Security questions, answered
What exactly does the SHA-256 seal cover?
The seal is computed over an immutable snapshot taken at the moment the last signer finishes: the final rendered document, the completed field values, and the signature marks themselves. Anything inside that snapshot is covered. Change one character of it later and the digest no longer matches.
Could CalmSign alter a document after it is signed?
Not without it showing. We are bound by the same arithmetic as anyone else — a change we made would produce a different digest and break the seal exactly as a change made by a signer would. Both parties also hold their own identical sealed copy, so neither side depends on our copy being honest.
Does a signer need an account to verify a document?
No. Signing needs no account and neither does verification. Anyone holding the signed copy or the signing link can see whether the seal is intact and download the audit certificate.
What does the audit trail record?
Creation, delivery, every opening, each signature, and each verification. Every event carries a UTC timestamp accurate to the second, the IP address it came from, and the browser and operating system that made the request. Signature events also carry the signer name and email address.
How long do you keep my documents?
For as long as you keep them. Documents do not expire and are not deleted on a schedule. When you delete one, it is removed from our systems rather than flagged as hidden, and copies already downloaded by you or by the signer remain verifiable because the seal travels inside them.
Are CalmSign signatures legally binding?
Yes. Electronic signatures are legally binding in most jurisdictions under laws like ESIGN (US), eIDAS (EU), and similar legislation worldwide. What makes a signature defensible in practice is evidence, which is the job the tamper seal and the audit trail do.
Do you hold specific compliance certifications?
This page describes the mechanisms in the product, not an attestation of them. If your procurement process needs a particular certification, questionnaire, or agreement, email hello@usecalmsign.com and ask — we would rather answer plainly than decorate a page with badges.
Start signing securely
Every document is tamper-proof from day one. Free to start.
Create free account