Every signature records the signer's explicit consent to sign electronically, their email identity, timestamp (UTC), IP address and browser. This evidence package satisfies ESIGN & UETA (US), PIPEDA and provincial electronic-transactions acts (Canada) and eIDAS simple electronic signatures (EU).
We compute a SHA-256 hash of the original PDF when it's uploaded and of the sealed PDF when it completes. Both are printed on the certificate of completion, so any later modification is detectable.
Appended to every signed document: document ID, signers, view/sign times, IPs, devices, each signature image and the full event log.
All traffic is TLS 1.2+. Documents are stored on isolated, access-controlled infrastructure in North America with daily backups.
Signing links are unguessable 32-character tokens tied to one signer and one document. Sender accounts use passwordless email sign-in with short-lived, single-use links. API keys are stored hashed.
Every webhook is signed with HMAC-SHA256 over the timestamp and body so your systems can verify it came from Signit and hasn't been replayed.
Senders can delete any document at any time, which permanently removes the original and signed files. Signers can request deletion by email. Enterprise plans can set custom retention policies.
We do not sell personal data and never use document contents for any purpose other than providing the service. See the privacy policy.
Questions or a security questionnaire to complete? Email signitpdf@gmail.com.