Understand how document access, recipient verification, activity records, and completed copies work—and where their limits are.
Email verification
Access controls
Audit trails
Completion records
Document privacy and access
New workspace document uploads use private storage rather than permanent public file links.
Document owners and administrators can access the workspace records permitted by their role. External recipients use their individual signing link and verified signing session.
Authorized document requests receive temporary download links. Treat those links as sensitive while they are valid.
The account-free PDF tool processes your selected PDF locally in your browser; it does not upload the PDF to our server.
Signer verification
Each recipient receives an individual signing link.
An email code confirms access to the recipient mailbox before signing.
Verification codes expire and failed attempts are limited.
Email verification is not a government identity check and does not establish signing authority.
Audit events and timestamps
Activity includes recorded sending, viewing, signing, declining, voiding, and completion events, with timestamps and available actor or request information.
The completion record includes recipient signing dates and the document completion date where recorded.
Completed envelopes provide a signed download and a completion record. Download and retain those records together.
An event timestamp describes a recorded action; it does not independently prove legal identity, authority, consent, or enforceability.
Document integrity
The original document is hashed when sent.
Signed downloads check the source document against its recorded hash.
Once signing is complete, the signing workflow rejects further recipient field changes.
The source hash is not a cryptographic seal of the final signed PDF. It does not establish that a downloaded copy has never been edited.
Store the completed document and its associated signing records together.
Account and signing-session security
Senders sign in to their account to use the workspace. Recipient email codes protect the separate signing session, not the sender account login.
Verified signing sessions expire, and signing links should not be forwarded or verification codes shared.
Recipient mailbox verification should not be treated as an account-level two-factor login. Protect your email account and use the available account-security controls.
Retention, deletion, and voiding
The current signing workflow does not promise an automatic document-purge schedule. Keep your own completed records for the period required by your policies and applicable obligations.
Senders can delete draft envelopes from the document list. Sent requests can be voided; voiding stops the active request and is not the same as erasing its stored files or activity history.
Deleting a draft envelope record should not be treated as proof that all associated files have been purged. Contact the team about broader document or account deletion requests.
Responsible use
Designed to help create clear electronic signing records.
Provides audit trails and completion records for document transactions.
Legal requirements vary by jurisdiction, document type, consent, intent, authentication, and retention practices.
Consult qualified legal counsel for important transactions or regulated use cases; no universal compliance or certification is claimed.
Report a concern
Use the Contact page to report a suspected security issue.
Describe the affected feature without sharing passwords, signing links, verification codes, or sensitive document contents.
Do not access other people’s documents or accounts when reporting a concern.
Questions about security?
Ask about document access, signing records, or a deletion request. For legal or regulatory requirements, consult a qualified adviser.