# Signatures that hold up — with the record to prove it

> Why Tally Sign signatures hold up under the ESIGN Act and UETA: signer consent, a Certificate of Completion with IP and device, SHA-256 fingerprints.

Tally Sign signatures are electronic signatures under the U.S. ESIGN Act and UETA. Every signer agrees to sign electronically, and every signed PDF ends with a Certificate of Completion: who signed, when, from which IP address and device, and a SHA-256 fingerprint of what they signed.

[Get started](https://www.tallysign.com/signup) See a certificate

## Is it legally binding? — yes, and here's why

Electronic signatures have been legal in the United States since 2000 and across the EU since 2016. Here's what each rests on.

United States

### ESIGN Act and UETA

The federal ESIGN Act (15 U.S.C. § 7001) and the state laws based on the Uniform Electronic Transactions Act say a signature, contract or record can't be denied legal effect just because it's electronic. That covers sales contracts, order forms, NDAs, SOWs, leases and most other business agreements.

European Union

### eIDAS Regulation

A Tally Sign signature is a simple electronic signature under eIDAS. Under Article 25 it can't be denied legal effect or refused as evidence just because it's electronic. It isn't an advanced or qualified signature, so documents that require those need another tool.

Everywhere else

### Check the document's law

Most countries accept electronic signatures for commercial contracts. Whether a particular document is valid still depends on the law that governs it and what it says, so check with your lawyer for anything unusual.

### What e-signature isn't for

ESIGN leaves a few kinds of documents out, and some need a notary or a stronger signature. Use paper or a specialist service for these. The full terms signers agree to are in the [Electronic Records and Signature Disclosure](https://www.tallysign.com/legal/electronic-signature-disclosure).

- Wills, codicils and testamentary trusts
- Adoption, divorce and other family law matters
- Court orders, notices and official court documents
- Notices of utility shut-off, foreclosure, eviction, or cancellation of health or life insurance
- Product recall notices and documents that must travel with hazardous materials
- Anything that must be notarized, or signed with an EU qualified signature

## What each signature records — start to finish

If anyone ever asks whether a person really signed, the answer is in the record: a link sent only to them, their agreement to sign electronically, the signature they chose, and where and when they signed it.

1. A link only they receive Each signer gets their own signing link by email. Nobody needs an account. Each new send or hand-off makes new links, and the old ones stop working. Someone who starts from a company's public signing link confirms their email the same way, by opening a link emailed to them, unless the company turned that off; the certificate says which.
2. An access code, if you set one You can give a signer a code by phone or text. Their link shows nothing of the document until it's entered, five wrong tries lock it for 15 minutes, and the certificate records when the code was verified.
3. They agree to sign electronically Before they can fill in anything, signers read the electronic record disclosure and tick the box. It tells them how to get a paper copy and that they can decline instead.
4. A real view, not a link scanner A view counts only when the signer scrolls, clicks or types. Email security that opens links first is logged separately and left off the certificate.
5. They adopt a signature and confirm it They draw a signature or pick a typed one, then confirm that it's the legal equivalent of their handwritten signature on this document.
6. The moment is recorded Time, IP address and device are saved with the signature, and every step before it is in the audit trail.
7. Everyone gets the signed PDF When the last person signs, each signer and CC receives the signed PDF by email, with the Certificate of Completion at the end.

## The certificate — on every signed PDF

Every signed PDF ends with a Certificate of Completion. This is a real one, made by Tally Sign for the sample order form on this site. Yours are in your signers' language, with your logo and colors.

1. The document fingerprint A SHA-256 fingerprint of the exact content that was sent, with its exhibits. A new version gets a new fingerprint.
2. Every signer Name, email, title and company, the signature they adopted, when they consented, viewed and signed, when they entered an access code, their IP address and device, and each file they uploaded with its SHA-256.
3. The audit trail Each event with a UTC timestamp to the millisecond: sent, emailed, viewed, signed, reminders, edits accepted, hand-offs and the signed PDF's own hash.

What you're seeing: the Certificate of Completion for Northbeam Software's order form, signed by Avery Brooks on a Mac and by Dana Whitfield of Brightline Logistics on an iPhone, with the document fingerprint, each signer's consent, view and signing times, IP addresses and devices, and the audit trail. Names and addresses are fictional.

## Proof it wasn't changed — before or after signing

A signature belongs to one exact version of a document. Tally Sign makes sure nobody can swap the content underneath it, and keeps what you need to show that.

### Frozen when it's sent

Sending freezes the document's content and exhibits and fingerprints them. Nobody can edit a sent document in place.

### Signatures follow the version

Each signature is checked against the version the signer read. If the document changed in the meantime, the signature isn't accepted.

### Changes are on the record

Accepting a redline makes a new version with its own fingerprint. Unlocking a document to edit it stops signing, clears signatures and is logged.

### Signed documents stay

Completed and declined documents can't be edited or deleted. Only drafts and voided documents can.

### Check any copy

The SHA-256 of the signed PDF is recorded. Anyone can drop a copy on the Verify a document page to see if it's the exact file Tally Sign produced.

### Every version kept

Earlier versions stay with the document, with exactly what changed between them and who accepted it.

[Verify a signed PDF](https://www.tallysign.com/verify)

## Your team's accounts — locked to your company

Sign in with your identity provider, see every new browser, and decide who can do what.

### Single sign-on on every plan

SAML 2.0 or OpenID Connect with Okta, Microsoft Entra ID, Google Workspace and others. Require it for everyone, and your identity provider's MFA applies.

### Passwords and sessions

Passwords are stored only as salted scrypt hashes. Repeated wrong passwords are blocked for 15 minutes, and changing a password signs out every other browser.

### Two-step sign-in and alerts

A code from an authenticator app after the password, with single-use recovery codes; admins can require it for everyone. Everyone is emailed when their account signs in from a new browser.

### Roles

Owners, admins and members. Each request reaches only your own company's data, from the app, the API or Salesforce.

### Keys and connections

API keys are stored only as hashes, rate-limited and revocable, and API webhooks are signed. ChatGPT and Claude ask before sending anything, and an admin can disconnect them all at once.

### Encrypted secrets

Salesforce tokens and single sign-on secrets are encrypted with AES-256-GCM. Everything travels over HTTPS, with HSTS.

## Your data — where it lives and who touches it

Everything is stored in the United States, with a short list of providers and commitments written into the Data Processing Addendum.

### Stored in the United States

The app and database run in Railway's US West region in California, and files are in private storage in San Jose. Daily backups are kept up to 3 months.

### Four subprocessors

Railway for hosting, Resend for email, and OpenRouter with Anthropic Claude hosts for the AI assistant, only when someone uses it.

### Not used to train AI

We don't train AI models on your documents or your signers' data, and our AI providers' terms don't allow them to either.

### Yours to take or delete

Download every signed PDF with a CSV of who signed what, any time, even while paused. The owner can delete the company from Settings.

### Told within 72 hours

If a breach affects your data, we tell you without undue delay and within 72 hours, as the Data Processing Addendum commits.

### Written down

The Data Processing Addendum's Annex II lists every security measure in place, and every one that isn't yet.

[Data Processing Addendum](https://www.tallysign.com/legal/data-processing-addendum) [Subprocessors](https://www.tallysign.com/legal/subprocessors) [Privacy Policy](https://www.tallysign.com/legal/privacy-policy) [E-signature disclosure](https://www.tallysign.com/legal/electronic-signature-disclosure)

## Not in place yet — said plainly

If your security review needs one of these, tell us. The complete list is in Annex II of the [Data Processing Addendum](https://www.tallysign.com/legal/data-processing-addendum).

- A SOC 2 report or ISO 27001 certification
- Signer identity checks beyond email and access codes, such as SMS codes or ID document checks
- Qualified electronic signatures under eIDAS, and remote online notarization

## Questions

Security questionnaires and vulnerability reports go to [security@tallysign.com](mailto:security@tallysign.com).

### Are Tally Sign signatures legally binding?

Yes, for business agreements such as order forms, NDAs, SOWs and leases. They're electronic signatures under the U.S. ESIGN Act and state UETA laws, and simple electronic signatures under the EU's eIDAS Regulation. A few documents, such as wills, court documents and anything that must be notarized, need another way to sign.

### What if someone says they didn't sign?

The certificate shows the signing link went to their email address, that they agreed to sign electronically, when they opened the document and signed it, the IP address and device they used, and the signature they adopted. If you gave them an access code, it also shows when the code was entered, so opening the document took something sent outside email too. That's the evidence e-signature disputes turn on.

### How can I check a signed PDF hasn't been changed?

Drop it on the Verify a document page (/verify). Your browser fingerprints the file without uploading it, and Tally Sign says whether it's the exact signed PDF it produced. The same SHA-256 is in the document's audit trail and in the export of your signed documents, so you can also run shasum -a 256 on a copy (or certutil -hashfile on Windows) and compare.

### Do signers need an account?

No. They sign in the browser on a phone, tablet or computer from the link in their email. They can also sign in person on your device, and the certificate records whose device it was. The signing page is built to WCAG 2.2 AA; see the accessibility statement.

### Where is our data stored?

In the United States: the app and database in Railway's US West region in California, and files in San Jose. There's no choice of region today.

### Do you support multi-factor authentication?

Yes. Two-step sign-in asks for a code from an authenticator app such as Google Authenticator, Microsoft Authenticator or 1Password after the password, with 10 single-use recovery codes. Anyone can turn it on, and owners and admins can require it for everyone, including sign-ins with Google, Microsoft and Salesforce. With single sign-on, your identity provider's MFA applies.

### Do you have SOC 2?

Not yet. Annex II of the Data Processing Addendum describes the security measures in place and the ones that aren't. Send your questionnaire to security@tallysign.com and we'll answer it.

### Can we use it for health information?

No. Tally Sign isn't built for protected health information under HIPAA and doesn't sign business associate agreements, so keep PHI out of documents you send with it.

### How do I report a vulnerability?

Email security@tallysign.com. We acknowledge reports within 5 business days. The address is also in /.well-known/security.txt.

## Step-by-step guides

Tally Sign Support walks through each part with screenshots of the real product.

[All guides](https://www.tallysign.com/support?view=guides)

- [Security and your data](https://www.tallysign.com/support/admin/security-and-your-data): Admin · Where your documents are stored, encryption, the audit trail, signer access codes, sign-in options and how long data is kept.
- [Send a document and track it](https://www.tallysign.com/support/getting-started/send-and-track): Getting started · Send for signature in your customer's language, ask for an access code, see who opened and signed it, remind people, download the signed PDF and check a copy later.
- [What your customer sees when signing](https://www.tallysign.com/support/getting-started/what-your-customer-sees): Getting started · The signing page from the signer's side: consent, fields, adopting a signature, finishing and their language.
- [Single sign-on](https://www.tallysign.com/support/admin/single-sign-on): Admin · Let your team sign in through Okta, Microsoft Entra ID, Google Workspace or any SAML 2.0 or OpenID Connect provider, test it, then turn it on or require it.

Source: https://www.tallysign.com/security
