Signing
Audit certificate
A signature is only as good as what you can show about how it happened.
- Applies to
- All signed documents
- Attached to
- The executed document
What it does
Every executed document carries an audit certificate recording signer IP, intent-to-sign consent, timestamps, SHA-256 fingerprint, retained for 24 months.
The certificate is what turns a signed PDF into something you can rely on later. It travels with the executed copy rather than living in a separate log somebody has to go and find.
What the fingerprint is for
The SHA-256 fingerprint records what was actually signed. If a copy of the document turns up later and anyone questions whether it is the same file, the fingerprint answers it: a single changed byte produces a different hash.
That is the difference between a certificate that says a signature happened and one that ties the signature to a specific document.
What it does not do
Questions
Audit certificate, answered
No. Every executed document carries one.
With the executed document, retained rather than held in a separate system.