Trust

Trust, by design.

Most e-sign tools rent trust — a wall of badges, a logo strip, a "verify on our site" portal. MostlySign builds it in. Every completed document carries its own proof: a full audit trail, a real cryptographic seal, and a trusted timestamp that any PDF reader in the world can check.

Completed documents are PAdES-sealed and RFC 3161 timestamped — verifiable in Adobe Reader & the EU DSS validator, not just here.
The audit trail

What every envelope captures.

Signing isn't a single click — it's a chain of recorded events. We capture that chain and print it on the certificate of completion that travels with the sealed PDF. Nothing is inferred after the fact; each row is written the moment it happens.

Captured on every signer event
Signer identity
Name and email the invite was sent to and opened from.
Timestamps
Sent, opened, viewed and signed — each to the second, in UTC.
IP address
The network address each action was taken from.
Email & delivery
Where the request went and the address it was accepted at.
Consent to sign electronically
The signer's explicit agreement to use an electronic signature (ESIGN / UETA).
Document hash
A cryptographic fingerprint of the exact bytes that were signed.
MostlySign
Certificate of completion
#MS-4821
Sent to signers09:02:11Z
Viewed · 203.0.113.709:14:38Z
Consent accepted09:15:02Z
Signed by M. Rivera09:15:44Z
Sealed · PAdES + RFC 316109:15:45Z
Document hash a3f2…9c
The seal

A real digital signature — not a picture of one.

When every party has signed, we seal the final PDF with two standards you'll never have to think about. Here's what they actually do, in plain English.

PAdES
A cryptographic seal on the bytes

PAdES (PDF Advanced Electronic Signatures) embeds a digital signature over the exact contents of the finished document. It's the ISO/EU standard for signing a PDF — the same mechanism Adobe and government portals rely on.

RFC 3161
A trusted timestamp

An RFC 3161 timestamp from an independent authority proves the document existed, sealed, at a specific moment — so "when" is anchored to a third party's clock, not ours. It keeps the seal verifiable long after signing.

Tamper-evidence
Any later edit breaks the seal

The seal is computed from the document's bytes. Change a single character afterwards — a date, a number, a name — and the signature no longer matches. Any validator flags it instantly. Tampering doesn't get hidden; it gets exposed.

The difference that matters

Verifiable anywhere — not just here.

This is the whole point. A sealed MostlySign document isn't locked to a MostlySign portal. Because the seal is a standards-based PAdES signature, it validates in the tools people already trust:

Adobe Acrobat Reader — the signature panel shows it as valid against Adobe's trust list (AATL).
The EU DSS validator — the European Commission's independent, public validation service. Nothing of ours involved.

We are deliberately not a "verify our document on our website" portal. That's circular — the point of a real seal is that you don't have to take our word for it.

Valid signature
PAdES · a3f2…9c
Is it legally binding?

Yes — electronic signatures hold up.

In most of the world, a document signed electronically is as enforceable as one signed in ink. MostlySign signatures are made under the frameworks that establish this:

United States
ESIGN Act & UETA — electronic signatures and records carry the same legal effect as handwritten ones.
European Union
eIDAS — an electronic signature can't be denied legal effect just for being electronic (Article 25).
To be precise: MostlySign provides standard electronic signatures with a document seal and audit trail. We do not perform government-ID or knowledge-based identity proofing, and we don't offer notarization or eIDAS "advanced" / "qualified" signatures. For the vast majority of agreements — NDAs, contracts, offers, consents — a standard e-signature is exactly what's needed and what the law recognises. If your use case specifically requires qualified signatures or notarization, that's a different product.
Where your data lives

EU data residency, by default.

MostlySign runs on Google Cloud / Firebase, with compute and storage in the europe-west2 (London) region. Your documents, audit trails and account data are processed and stored there — EU data residency is the default, not an add-on you have to ask for.

And because the proof travels with the document, residency isn't the whole story: the PAdES seal and audit trail are embedded in the sealed PDF itself, so a completed document stays verifiable wherever it ends up — no dependency on where a server happens to sit.

Straight talk: we don't yet hold formal certifications like SOC 2 or ISO 27001, and we won't pretend otherwise. What we do offer is honest, standards-based practice: EU-hosted data, encryption in transit and at rest, and a Data Processing Agreement available to Business customers.

Trust you can hand off.

Send a document, watch it get sealed, and hand the recipient proof that stands on its own — anywhere they choose to check it.

Send your first document — free Back to home →