Compliance
Last updated June 20, 2026
Doc Sign Flow is designed to support widely-recognized electronic-signature frameworks as the product matures. This page explains how our approach maps to the major laws and standards that govern e-signatures, what evidence we capture on every document, and where our current limits are. It is informational and not legal advice — you remain responsible for confirming that a given signature meets the requirements of your jurisdiction and use case.
ESIGN Act & UETA (United States)
The US ESIGN Act and the Uniform Electronic Transactions Act (UETA) give electronic signatures the same legal standing as handwritten ones when four elements are present: intent to sign, consent to do business electronically, association of the signature with the record, and retention of that record. Doc Sign Flow captures each of these — explicit consent at signing, a clear act of signing, and an associated record with timestamps, IP address, and a certificate of completion attached to the final PDF.
eIDAS (European Union)
Under the EU's eIDAS regulation, electronic signatures fall into three tiers: simple (SES), advanced (AdES), and qualified (QES). Doc Sign Flow provides simple electronic signatures today, backed by consent capture and a tamper-evident audit trail suitable for the everyday agreements most businesses sign. Advanced identity verification and qualified signatures, which require a certified trust service provider, are on our roadmap rather than available now.
GDPR readiness
We take a privacy-first approach: we minimize the personal data we collect, keep secrets and keys server-side, encrypt documents in storage, and honor deletion requests. Signers are told who is requesting a signature and why, and account holders can remove documents and data associated with their account.
Audit trail & evidence
Every document carries a complete activity history — when it was sent, viewed, signed, and downloaded, and from which IP address. This record is compiled into a certificate of completion that travels with the signed PDF, giving you defensible evidence of who did what and when.
Tamper-evidence
Every completed PDF is sealed with a SHA-256 hash recorded in the audit trail. Because any change to the file would change its hash, later alterations are detectable — a core requirement for treating a signed document as trustworthy evidence.
Important note
Doc Sign Flow is not yet a certified Qualified Trust Service Provider, and does not currently offer qualified electronic signatures (QES) or notarization. For high-assurance, regulated, or cross-border transactions with strict identity requirements, consult a qualified legal professional before relying on any e-signature platform, including ours.