Most e-sign tools rent trust — a wall of badges, a logo strip, a "verify on our site" portal. MostlySign builds it in. Every completed document carries its own proof: a full audit trail, a real cryptographic seal, and a trusted timestamp that any PDF reader in the world can check.
Signing isn't a single click — it's a chain of recorded events. We capture that chain and print it on the certificate of completion that travels with the sealed PDF. Nothing is inferred after the fact; each row is written the moment it happens.
When every party has signed, we seal the final PDF with two standards you'll never have to think about. Here's what they actually do, in plain English.
PAdES (PDF Advanced Electronic Signatures) embeds a digital signature over the exact contents of the finished document. It's the ISO/EU standard for signing a PDF — the same mechanism Adobe and government portals rely on.
An RFC 3161 timestamp from an independent authority proves the document existed, sealed, at a specific moment — so "when" is anchored to a third party's clock, not ours. It keeps the seal verifiable long after signing.
The seal is computed from the document's bytes. Change a single character afterwards — a date, a number, a name — and the signature no longer matches. Any validator flags it instantly. Tampering doesn't get hidden; it gets exposed.
In most of the world, a document signed electronically is as enforceable as one signed in ink. MostlySign signatures are made under the frameworks that establish this:
MostlySign runs on Google Cloud / Firebase, with compute and storage in the europe-west2 (London) region. Your documents, audit trails and MostlySign records are processed and stored there — UK data location is the default, not an add-on you have to ask for. Sign-in (Firebase Authentication) and your Mostly Tiny account are in the United States.
And because the proof travels with the document, where the data sits isn't the whole story: the PAdES seal and audit trail are embedded in the sealed PDF itself, so a completed document stays verifiable wherever it ends up — no dependency on where a server happens to sit.
These are the only third parties MostlySign uses to run the service. Each is bound by data-protection terms, and we tell Business customers at least 30 days before we add or replace one.
The people you send documents to are your recipients, not our sub-processors. The full terms are in our Privacy Policy and, for Business customers, the Data Processing Agreement.
A signed document is only worth something if its proof survives, so we keep it for as long as your account is open — and no longer.
Stripe keeps payment records as its own legal obligations require, and hosting request logs are kept for up to 12 months. Details are in our Privacy Policy.
Send a document, watch it get sealed, and hand the recipient proof that stands on its own — anywhere they choose to check it.