Start free

Blog

When you do not need a certificate for an agreement to hold up

E-SIGN and UETA ask for five things, and none of them is a certificate. What they do ask for, and what a record has to show to satisfy each.

A signed paper agreement in a clear archive sleeve on a shelf among labelled binders, lit by a single shaft of light.

Most of the agreements small businesses take are between them and their own customer: a waiver, a rental agreement, a work authorisation, a house rule. No third party validates them automatically. Nobody's system rejects them. They sit in a file until either nothing happens — which is most of the time — or somebody disputes one.

For those, the question is not "does it validate in Adobe". It is "if this is challenged, what can we show". Here is what the statutes ask for, and what a record has to contain to answer each one.

1. Intent to sign

The person meant to sign, rather than clicking something they did not understand to be a signature. Typing a name into a box labelled signature, under text that says what signing means, is intent. A pre-ticked checkbox at the bottom of a page is a much weaker version of the same claim.

What the record should show: the act, separately from everything else on the page, with a timestamp.

2. Consent to do business electronically

E-SIGN wants the signer to have agreed to electronic records, to have been told they can ask for a paper copy, and — this is the part that gets skipped — for that consent to have happened before the signature, not as part of it.

A single form with "I agree to sign electronically" as a checkbox beside the signature box is one act. Two separate acts, in order, is what the statute describes.

What the record should show: consent as its own event, with its own timestamp, earlier than the signature event.

3. Attribution

That the signature was the act of that person. This is where evidence does the work, because there is no way to prove who was holding a phone. What you can show is a chain of circumstances that is hard to explain any other way: a link sent to an address only they control, opened from a device, a name typed that matches, from a network address, at a time.

What the record should show: how the link reached them, when it was opened, where from, and what they typed.

4. Association with the record

That the signature belongs to this document and not another one. A scanned signature at the end of a PDF is weak here — it can be moved. A signature recorded against a fingerprint of the exact text that was displayed cannot be moved to a different document without the fingerprint failing.

What the record should show: a hash of the document as displayed, in the signature event itself.

5. Retention

That the record can be reproduced accurately, by both parties, for as long as it matters. A PDF in a folder is retention. A PDF in a folder somebody can edit is not, quite.

What the record should show: that the events cannot be altered after the fact — and ideally that this is checkable by somebody who does not trust you.

What this adds up to

None of those five is a certificate. Four of them are about what happened, and the fifth is about whether the account of what happened can be trusted later.

That is why a signing product's real job is evidence, and why "we collect signatures" is a much smaller claim than it sounds. Anybody can collect a signature. The question is what is around it.

Where a certificate is still worth having

Two cases, and they are narrow:

For a kayak waiver signed on a Saturday morning, neither applies.

SignSealer is not a law firm and this is not legal advice.


More writing · Who SignSealer is for