Trust

Trust, by design.

Most e-sign tools rent trust — a wall of badges, a logo strip, a "verify on our site" portal. MostlySign builds it in. Every completed document carries its own proof: a full audit trail, a real cryptographic seal, and a trusted timestamp that any PDF reader in the world can check.

Completed documents are PAdES-sealed and RFC 3161 timestamped — verifiable in Adobe Reader & the EU DSS validator, not just here.
The audit trail

What every envelope captures.

Signing isn't a single click — it's a chain of recorded events. We capture that chain and print it on the certificate of completion that travels with the sealed PDF. Nothing is inferred after the fact; each row is written the moment it happens.

Captured on every signer event
Signer identity
Name and email the invite was sent to and opened from.
Timestamps
Sent, opened, viewed and signed — each to the second, in UTC.
IP address
The network address each action was taken from.
Email & delivery
Where the request went and the address it was accepted at.
Consent to sign electronically
The signer's explicit agreement to use an electronic signature (ESIGN / UETA).
Document hash
A cryptographic fingerprint of the exact bytes that were signed.
MostlySign
Certificate of completion
#MS-4821
Sent to signers09:02:11Z
Viewed · 203.0.113.709:14:38Z
Consent accepted09:15:02Z
Signed by M. Rivera09:15:44Z
Sealed · PAdES + RFC 316109:15:45Z
Document hash a3f2…9c
The seal

A real digital signature — not a picture of one.

When every party has signed, we seal the final PDF with two standards you'll never have to think about. Here's what they actually do, in plain English.

PAdES
A cryptographic seal on the bytes

PAdES (PDF Advanced Electronic Signatures) embeds a digital signature over the exact contents of the finished document. It's the ISO/EU standard for signing a PDF — the same mechanism Adobe and government portals rely on.

RFC 3161
A trusted timestamp

An RFC 3161 timestamp from an independent authority proves the document existed, sealed, at a specific moment — so "when" is anchored to a third party's clock, not ours. It keeps the seal verifiable long after signing.

Tamper-evidence
Any later edit breaks the seal

The seal is computed from the document's bytes. Change a single character afterwards — a date, a number, a name — and the signature no longer matches. Any validator flags it instantly. Tampering doesn't get hidden; it gets exposed.

The difference that matters

Verifiable anywhere — not just here.

This is the whole point. A sealed MostlySign document isn't locked to a MostlySign portal. Because the seal is a standards-based PAdES signature, it validates in the tools people already trust:

Adobe Acrobat Reader — the signature panel reads the seal, confirms the document hasn't changed since it was sealed, and shows the timestamp.
The EU DSS validator — the European Commission's independent, public validation service. Nothing of ours involved.

We are deliberately not a "verify our document on our website" portal. That's circular — the point of a real seal is that you don't have to take our word for it.

One honest caveat about the trust anchor

Our seal certificate is issued by Mostly Tiny — it is not yet from a certificate authority on Adobe's AATL list or an EU trusted list. So a reader will confirm the seal is intact and the document unaltered, but it will flag the issuer as one it doesn't already know, until our certificate is added to your trust store. What the seal proves today is integrity and time — that these exact bytes existed, sealed, at a timestamped moment — not a third party's vetting of who we are. We'd rather say that than let you find it out in Acrobat.

Valid signature
PAdES · a3f2…9c
Is it legally binding?

Yes — electronic signatures hold up.

In most of the world, a document signed electronically is as enforceable as one signed in ink. MostlySign signatures are made under the frameworks that establish this:

United States
ESIGN Act & UETA — electronic signatures and records carry the same legal effect as handwritten ones.
European Union
eIDAS — an electronic signature can't be denied legal effect just for being electronic (Article 25).
To be precise: MostlySign provides standard electronic signatures with a document seal and audit trail. We do not perform government-ID or knowledge-based identity proofing, and we don't offer notarization or eIDAS "advanced" / "qualified" signatures. For the vast majority of agreements — NDAs, contracts, offers, consents — a standard e-signature is exactly what's needed and what the law recognises. If your use case specifically requires qualified signatures or notarization, that's a different product.
Where your data lives

Documents stored in the UK, by default.

MostlySign runs on Google Cloud / Firebase, with compute and storage in the europe-west2 (London) region. Your documents, audit trails and MostlySign records are processed and stored there — UK data location is the default, not an add-on you have to ask for. Sign-in (Firebase Authentication) and your Mostly Tiny account are in the United States.

And because the proof travels with the document, where the data sits isn't the whole story: the PAdES seal and audit trail are embedded in the sealed PDF itself, so a completed document stays verifiable wherever it ends up — no dependency on where a server happens to sit.

Straight talk: we don't yet hold formal certifications like SOC 2 or ISO 27001, and we won't pretend otherwise. What we do offer is honest, standards-based practice: documents hosted in the UK (London), encryption in transit and at rest, and a Data Processing Agreement available to Business customers.
Who else touches your data

Every sub-processor, named.

These are the only third parties MostlySign uses to run the service. Each is bound by data-protection terms, and we tell Business customers at least 30 days before we add or replace one.

Google Cloud & Firebase
Hosting, database, document storage, functions and sign-in.
UK (London); sign-in in the US
Stripe
Payments and the billing details you enter at checkout.
United States and EU
Resend
Delivers signature requests, reminders, completion notices and sign-in email.
United States
DigiCert
The RFC 3161 timestamp authority. It receives only a cryptographic hash of a completed document — never the document or its contents.
United States
Cloudflare
DNS, network security, bot checks on the support form, and our status page.
Global edge network
PostHog (EU Cloud)
Product analytics inside the app — only if you consent to analytics cookies.
EU (Germany)
Fathom Analytics
Cookie-free page-view statistics for this website. No personal profile is built.
Canada

The people you send documents to are your recipients, not our sub-processors. The full terms are in our Privacy Policy and, for Business customers, the Data Processing Agreement.

How long we keep it

Kept while you need it. Deleted when you leave.

A signed document is only worth something if its proof survives, so we keep it for as long as your account is open — and no longer.

While your account is open, we keep each envelope, its sealed PDF and its audit trail — they are how a signature is proven later.
When you close your account, pending signature requests are cancelled and API keys disabled at once. Your envelopes, sealed PDFs, audit trails, templates and keys are permanently deleted 30 days later.
Signers keep their own copy. Everyone who signs is sent the sealed PDF when signing completes, and it verifies without us — so closing your account never takes anyone's proof away.

Stripe keeps payment records as its own legal obligations require, and hosting request logs are kept for up to 12 months. Details are in our Privacy Policy.

Talk to us

Security and privacy.

Report a security issue
Email security@mostlytiny.io. Our security.txt has the details. Please give us a chance to fix a problem before you disclose it.
Privacy questions and data requests
Email privacy@mostlytiny.io to access, correct or delete your data.
Service status
Live status and incident history are at status.mostlytiny.io, hosted apart from the product so it stays up when we are down.
Everything else
Questions about your account or a document go to support.

Trust you can hand off.

Send a document, watch it get sealed, and hand the recipient proof that stands on its own — anywhere they choose to check it.

Send your first document — free Back to home →