
E-signature, built the other way round
Anyone can collect a signature. What makes one hold up is the record around it — and most products treat that as a log. We built the record first and the signature is a row in it.
Three things, in that order, and each one leaves a record the next one is built on.
A link by text or email, a tablet handed across the counter, or a call from your booking system. The signer reads the whole text, agrees to sign electronically as its own step, then signs.
Every completed agreement gets a certificate with a code. Anybody holding the document can check it at signsealer.com/verify — no account, no call to us. It is re-derived from the record when checked, so a change shows.
The text's fingerprint is written into every event, the trail is hash-chained and append-only, and the sealed PDF carries the certificate. Nothing here can be edited afterwards, by you or by us.
However the document reaches the person, the same engine records the same evidence, and the business sees one list.
Your booking system, point of sale or CRM starts the document with one API call and hears back on a webhook. The signer never sees a second product. Four calls, in the quickstart.
A link, personal to the signer, with a reminder after the days you set and the signed copy with its certificate when everyone has signed.
The same link by SMS, sent only with a consent the record keeps, from a number that answers STOP. Most waivers are signed on the phone in the car park.
The SignSealer tablet app for iOS and Android runs one form in kiosk mode behind a staff PIN, resets between guests, and keeps signing when the connection drops. Counters and kiosks.
Under ESIGN and UETA an electronic signature is enforceable when you can show five things. Signatures have been thrown out for missing the fourth — Ruiz v. Moss Bros. Auto Group, where the employer could not attribute the signature to the employee because the system kept no evidence of who was at the keyboard. SignSealer records evidence for all five, then seals it: every event carries the hash of the exact text, the trail cannot be edited afterwards, the finished PDF is sealed so that a changed byte shows, and an independent timestamp authority fixes the time of sealing.
They meant this act to be their signature.
They agreed to do business electronically — before signing.
The signature is attached to this record and no other.
It can be shown to be them.
The record can be accurately reproduced later.
Four decisions you can check rather than take on trust.
Not a checkbox beside the signature box. ESIGN requires consent to precede the transaction, and a system that records both in the same instant cannot show that it did.
A document edited after signing no longer matches, and we say so. The check recomputes the hash from the text rather than trusting a stored one — otherwise the one thing it exists to detect is the one thing it cannot see.
Revising makes a new version. Editing one in place changes what people signed last week, retroactively and invisibly, which is the single worst thing a signing system can do.
Hash-chained per customer, so removing or altering a row breaks every row after it. A record that can be edited is a record of what somebody was willing to leave behind.
The morning list. Every document with who has signed and who it is still waiting on, so the queue at eight is a list on a phone, not a clipboard. This is the real screen, on an example account.

One page, no app to install, no account to make. It loads no script and nothing from anybody else, which you can check in its headers.
Shown in full and scrolled before anything else is asked. What will be recorded is one tap away, in plain words, with the text's fingerprint beside it.
"I agree — continue" is a separate press with its own time, so the record can show consent came before the signature rather than assert it.
Typed, and the name is checked against who the link was sent to. A copy goes to their email, with the certificate once everyone has signed.
Not another generic envelope. Two shapes, built once, because a waiver operation and a vacation rental are the same problem described with different nouns.
The guest list, the rental agreement, the house rules and the hot-tub waiver — for four people, two of them children — behind one link, with one state your lock or your PMS can wait on.
A tablet you hand across, a link on your site, or a call from your booking system. Works when the network does not, and the evidence says so rather than pretending otherwise.







What the law asks of an electronic signature, and how to run waivers and agreements so the record survives the day somebody disputes one.

AATL is a trust list inside Adobe Reader, not a legal standard. Here is what it does, what it does not do, and why most agreements never need it.

E-SIGN and UETA ask for five things, and none of them is a certificate. What they do ask for, and what a record has to show to satisfy each.

The queue at eight in the morning is people who did not get a text. What actually moves signing from the counter to the sofa the night before.
Nothing yet, and nothing invented. SignSealer is new; when customers have used it long enough to have an opinion worth reading, theirs will be here — the critical ones included, with our reply beside them. How reviews work here →
Idempotency with Stripe's semantics, signed webhooks with a real retry ladder, and a reference generated from the router so it cannot drift from what the code actually validates.
Same key and body replays. A different body is refused rather than absorbed — because absorbing it means you believe your second request happened, and it did not.
Six attempts on a widening ladder, then the delivery is dead and stays readable. You can see what was missed instead of guessing.
No "full access". A booking integration gets signing:subjects,
which is "decide who my guests are", not "act on my behalf".

Free for the first 25 agreements a month. No card to start.