Signer evidence and legal effect
What Stoatify records for each signer and what to preserve if a signature is challenged.
5 min read · Updated July 13, 2026
Stoatify records evidence around the signature, not just the visible mark on the page. That evidence helps connect the signing act to the recipient, preserve the agreed terms, and show whether the completed PDF changed later.
Evidence captured for each signer
- The recipient's name and email address.
- Use of a private 256-bit signing link issued only for that signer. Stoatify stores a SHA-256 hash of the secret rather than the raw secret itself.
- The time the request is first opened and the time the signer selects Sign and complete.
- The signing session's IP address and browser user agent.
- The exact submitted field values, completed PDF, organization-level digital seal, and completion certificate.
What the identity evidence means
- A private link supports attribution to the channel where you delivered it. Like any emailed or messaged link, it can be forwarded or opened by someone else with access.
- The IP address, browser, and timestamps add session context. They do not uniquely identify a human by themselves.
Good to know
Stoatify's standard flow does not perform a government-ID and liveness check or issue an eIDAS qualified electronic signature. For high-value, regulated, notarized, or identity-sensitive agreements, pair the Stoatify record with the identity, authority, witness, notary, or qualified-signature process the transaction requires.
Why the signature can be legally binding
Laws such as the US E-SIGN Act, state UETA enactments, Ontario's Electronic Commerce Act, and the EU eIDAS Regulation generally recognize electronic records and signatures. The common evidence questions are whether the signer intended to sign, whether the act can be attributed to them, whether the signature is associated with the agreed terms, and whether the completed record can be retained and reproduced.
Stoatify is designed to support those questions with a deliberate Sign and complete action, private-link and session evidence, required-field validation, a completed PDF in the sender's Vault, a completion certificate, and an embedded cryptographic seal. A court still decides authority, capacity, admissibility, weight, and enforceability from the full transaction and the law that applies.
Tip
The detailed e-signature legal and technical guide includes the signing-flow graph, identity model, court process, product comparisons, and primary links to E-SIGN, UETA, eIDAS, PAdES, CMS, X.509, RFC 3161, and the other standards Stoatify uses.
If an agreement is challenged
- 1Preserve the original digital PDF. Do not rely on a printed or scanned copy, because it loses the embedded signature data.
- 2Download and retain the completion certificate, invitation email or message, drafts, approvals, correspondence, and performance records.
- 3Use Verify a signed document to confirm that the embedded signature still matches the PDF's signed byte ranges.
- 4Keep any separate evidence of identity, signing authority, witnessing, or notarization used for the agreement.
- 5Give counsel the complete record so they can connect the technical evidence to the parties, agreement, and governing law.
Good to know
This article explains Stoatify's product evidence. It is not legal advice, and document-specific formalities vary by jurisdiction and transaction type.