Signature certificate

Legally binding electronic signatures,
with the evidence to prove it.

Collect signatures inside the same PDF or web form your customers already fill in. Every signature comes with a signature certificate: the notice the signer agreed to, the signer's intent, a tamper-evident timeline and a public verification page, so the signed document holds up in the countries where you do business.

Included with invitations and workflows on paid plans · No separate e-signature tool · Works on phones and in embedded forms

Agreement recordedThe exact notice the signer agreed to, in their language, and when
Intent capturedDrawn, typed or uploaded, then adopted on submit
Tamper-evident timelineEvery event chained with SHA-256
Verify onlineA public page anyone can check, no account needed

Why it holds up

The four things a court looks for, recorded every time

Electronic signature laws around the world agree on the same basics. The certificate captures each one at the moment it happens.

1

Intent to sign

The signer draws, types or uploads a signature under the consent notice, then submits the form. Both moments are recorded, and submitting is what adopts the signature.

2

Consent to sign electronically

One sentence sits with every signature field: by signing and submitting, the signer agrees to sign electronically with the same legal effect as signing by hand. The wording shown, its version, its language and the time of submission are stored with the signing.

3

Signature tied to the record

The signature is embedded in the finished PDF. Its SHA-256 fingerprint and the document's fingerprint are recorded together, so any later change to the file no longer matches.

4

Kept and reproducible

The signed PDF, the certificate and the full timeline stay with the submission for as long as you keep it. A write-once copy of the certificate and its timeline is kept for seven years on top of that, and the verification page confirms the document from any computer.

Inside the signature certificate

One PDF that tells the whole story

Download it from your submissions, attach it to notification emails, share it by link or read it through the API.

Certificate ID and verification link

A 16-character identifier printed on the certificate and used by the public verification page.

Document fingerprint

The SHA-256 of the signed PDF (and of the final PDF when a workflow appends its approval record).

Who signed, and how we know

Name and email address, the identity level (today: the personal email link), IP address and browser.

The notice, word for word

The version the signer agreed to, quoted in full, with the language it was shown in and the time of agreement.

A hash-chained timeline

Link opened, pages viewed, signature applied, notice agreed, signature adopted, submitted, document rendered. Each entry carries the fingerprint of the one before it, so a removed or edited entry breaks the chain.

Workflow approvals

When the form is a step in a workflow, every approval decision and the final PDF's fingerprint join the same timeline.

Public verification

Anyone can check a signed document

Every certificate links to a verification page. It shows whether the evidence chain is intact, who signed (with the email address masked), the notice they agreed to and the timeline. Upload the PDF you received and the page tells you whether it is the file that was signed. No PlatoForms account is needed, and nothing you upload is kept.

Read the certificate guide

Where it is recognised

Accepted where you do business

PlatoForms signatures are simple electronic signatures backed by recorded evidence. This is the category most countries' e-signature laws recognise for everyday business documents: contracts, waivers, consent forms, applications, onboarding paperwork and approvals.

JurisdictionLegal basisPlatoForms signaturesGood to know
United States ESIGN Act (2000) and UETA, adopted by 49 states; New York uses ESRA Recognised Courts look for intent, consent, attribution and a retained record. The certificate records all four.
Canada PIPEDA Part 2 and provincial e-commerce laws such as Ontario's Electronic Commerce Act Recognised A "secure electronic signature" is required only for specific federal uses.
United Kingdom Electronic Communications Act 2000 and UK eIDAS Recognised Simple electronic signatures are admissible and widely used for commercial contracts.
European Union eIDAS Regulation (EU) 910/2014, as amended by Regulation (EU) 2024/1183 Recognised as a simple electronic signature Cannot be denied legal effect solely because it is electronic. Qualified signatures (QES) are a separate tier that PlatoForms does not offer yet.
Australia Electronic Transactions Act 1999 (Cth) and the state and territory Acts Recognised A reliable method that identifies the signer and shows their intention, with consent to the electronic method.
New Zealand Contract and Commercial Law Act 2017 Recognised Same test as Australia.
Singapore Electronic Transactions Act 2010 Recognised A "secure electronic signature" is a higher tier reserved for particular uses.
Hong Kong Electronic Transactions Ordinance (Cap. 553) Recognised for private agreements Dealings with government bodies generally require a recognised digital certificate.
Japan Act on Electronic Signatures and Certification Business (2000) Recognised Most contracts need no prescribed form, so a recorded electronic signature is generally effective. The Act's statutory presumption of authenticity is reserved for signatures under the signer's sole control and is not claimed here.
India Information Technology Act 2000 Effective for most agreements Contracts need no particular form and the record is admissible as evidence. The IT Act's defined "electronic signature" tier uses licensed certifying authorities; wills, negotiable instruments other than cheques, powers of attorney, trusts, real-estate conveyances and many government filings require it.
South Africa Electronic Communications and Transactions Act 2002 Recognised as an ordinary electronic signature Where a law itself demands a signature, an advanced electronic signature is required.
Brazil Law 14.063/2020 and MP 2.200-2 Recognised as a simple electronic signature Advanced and qualified levels apply to dealings with public bodies.

Not listed? Most countries with an e-commerce law modelled on the UNCITRAL framework recognise simple electronic signatures in the same way. Check your local rules for the specific document types that still require a certified or witnessed signature.

Before you rely on it

What not to sign this way, and what we do not offer yet

Being clear about the edges is part of being trustworthy. Use a qualified provider or paper for the documents below.

Documents to keep on paper or with a qualified provider

  • Wills and testamentary trusts
  • Powers of attorney and deeds that must be witnessed in person
  • Family-law documents: adoption, divorce, separation agreements
  • Court orders and court filings
  • Notarised documents
  • Negotiable instruments such as promissory notes and bills of exchange
  • Land and property transfers where the registry prescribes its own process
  • Notices that consumer law requires on paper: utility shut-off, foreclosure or eviction, insurance cancellation, product recalls, hazardous-materials handling

Qualified and advanced signatures

EU QES and AES, India's certified digital signature certificates, and similar tiers issued by licensed certificate authorities. If a regulator or counterparty requires one, PlatoForms is not the right tool for that document today. Support through a qualified trust service provider is on our roadmap.

Countries that mandate a licensed certificate

Some jurisdictions accept only signatures issued through a licensed certification authority for regulated contracts, for example China's "reliable electronic signature" or Russia's enhanced qualified signature. Check the rule for your document type first.

Stronger identity checks

Today the signer's identity rests on the personal email link (or the workflow task assigned to them) plus IP address and device. One-time text-message codes and government ID verification are planned as paid add-ons.

Questions people ask

Electronic signature FAQ

Are PlatoForms electronic signatures legally binding?
Yes, in the jurisdictions listed above and for documents that the law allows to be signed electronically. What makes a signature binding is not the drawing itself but the evidence around it: that the signer intended to sign, agreed to do so electronically, that the signature is tied to the document and that the record is kept. The signature certificate records each of those. This page is general information, not legal advice; check the rules for your document type.
What does the signature certificate contain?
The certificate ID and verification link, the signed document’s SHA-256 fingerprint, the signer’s name and email address with the identity level, IP address and browser, the notice they agreed to (quoted in full, with its version and language), the signature images, and the complete hash-chained timeline from link opened to document rendered. For workflow forms it also lists each approval decision and the final PDF’s fingerprint.
Can a third party verify a signed PDF without a PlatoForms account?
Yes. The verification link printed on the certificate opens a public page that shows whether the evidence chain is intact, who signed (with the email address masked), the notice they agreed to and the timeline. They can upload the PDF they received to confirm it is the exact file that was signed. Nothing uploaded is stored.
What happens if a signer later disputes the signature?
You produce the certificate. It shows the email link the signer used, the device and IP address, the time they agreed to sign electronically, the time the signature was applied and adopted, and the fingerprint of the document as it was when they signed. Because every timeline entry carries the fingerprint of the previous one, any entry edited or removed afterwards breaks the chain, which the verification page reports.
How do you know who signed?
When you send the form by invitation, the signature is tied to the personal link emailed to that address. In a workflow, it is tied to the task assigned to that person. A form filled in from its public link produces no certificate, because there is no record of who received the link. Stronger checks, a text-message code or a government ID check, are planned as add-ons.
Do you offer EU qualified electronic signatures (QES)?
Not yet. PlatoForms signatures are simple electronic signatures under eIDAS, which covers most business documents in the EU. Documents that specifically require a qualified signature need a qualified trust service provider; support for that is on our roadmap.
Which documents or countries are not suitable?
It is usually the document type rather than the country. Wills, powers of attorney needing a witness, family-law documents, court filings, notarised deeds, negotiable instruments and certain property transfers are excluded almost everywhere. A few countries accept only signatures issued through a licensed certificate authority for regulated contracts. The list above covers both.
Does the signer see anything different?
One sentence under each signature field, in the form’s own style and language: by signing and submitting, they agree to sign electronically with the same legal effect as signing by hand. No extra checkbox, no pop-up. It appears only when the form is sent through an invitation or workflow step that produces a certificate, and it works the same way on phones and in forms embedded on your website.
What about forms I published before this?
Forms published before the signature certificate was upgraded keep the certificate they had, and their signers see no change at all. Forms you create from now on get the new certificate automatically.
How long is the evidence kept?
The signed PDF, the certificate and the timeline stay with the submission for as long as it exists, under the data-retention setting of your team. A copy of the certificate and its timeline is also written to write-once storage when the certificate is issued and kept for seven years, so deleting the submission does not destroy the evidence, and the verification link keeps working for it.
How do I get the certificate to the other party?
Attach it to your notification email with the certificate variables, download it from the submission, create a sharing link, or read it through the API and webhooks. The certificate’s own verification link works for anyone.

Put a signature on the form you already have

Upload a PDF or start from a web form, add the Signature field, and the certificate comes with it.

This page is general information about electronic signature laws and how PlatoForms records signatures. It is not legal advice. Laws change and vary by document type; consult a lawyer about your situation. See also our Terms and Conditions for the Sign Services clause. Terms and Conditions.