A signature is worth what you can prove afterwards. Signater proves the identity of whoever signed with configurable factors, from a code by email to an advanced selfie with liveness detection.
Every validated factor is recorded in the audit trail and consolidated in the certificate of completion: forensic evidence of the act of signing.
Each factor covers a different angle of identity; together, they raise the bar to match the document's risk.
A 6-digit code lands in the signer's inbox and must be entered before signing.
The 6-digit code goes out as a text message, with routing across multiple providers and domestic and international coverage.
A shared secret you define and the signer must enter. Signing only proceeds with the correct password.
The signer signs with their own certificate (.pfx/.p12), and the signature is generated with their private key.
The signer takes a selfie with the device camera; the photo is attached to the certificate as visual evidence of the act.
The browser camera runs an active liveness check, tested against the ISO/IEC 30107-3 presentation-attack standard, confirming a real person is signing — not a photo or a recorded video.
The signer attaches their identity document — ID card, driver's license or passport — and it becomes part of the envelope's evidence, bound to the signature it backs.
Cross-checks the signing selfie against the document photo: the face that signs is the face on the ID.
The signer's IP address is resolved to city, region and country. When the browser allows it, coordinates come in too, with reverse geolocation.
Every invite gets its own link: the email one, the SMS one and the next-day reminder are all different — trackable and revocable at any time.
Identity document
The signer attaches an identity document — ID card, driver's license or passport — right inside the signing flow, front and back. The capture becomes part of the envelope's evidence, bound to the signature it backs.
Turn on facial biometrics and they cross-check the signing selfie against the document photo: the face that signs is the face on the ID.
Uploads that don't look like an identity document are turned away on the spot — so the evidence that reaches you is evidence that holds.
Liveness
The advanced selfie factor confirms there is a real person in front of the camera — not a photo or a replayed video — and binds the capture to the signing act.
The liveness check is tested against the ISO/IEC 30107-3 presentation-attack standard — the benchmark used to certify biometric security systems against photos, videos and masks.
Signing from a computer with no camera? The system issues a QR code on the spot: the signer points their phone at it, takes the selfie there and the flow picks up right where it left off.
The image and the verification result become evidence in the certificate of completion, alongside the other factors.
Verification codes
The code is generated and sent on the spot, through the channel the envelope owner picks — and it lives for 5 minutes. After that it expires and a new one must be requested.
The short window shuts the door on intercepted or reused codes: what reaches the signer's device only works in that moment.
Sender password
The envelope owner sets a password only they and the signer know — agreed on outside the flow, in a channel both already use.
They can also leave a hint shown on the signing screen, like "Tax ID — numbers only": the right signer gets it instantly, no questions needed.
Own digital certificate
Signers can register their digital certificate on their own account: the file upload and the password happen a single time.
Every signature after that is one click — no re-attaching the .pfx, no retyping the password. The certificate is stored with its password encrypted at rest.
Geolocation
With the browser's permission, the signature records the signer's coordinates at the moment of the act — latitude and longitude right in the certificate of completion.
For anyone signing in the field — the driver in the yard, the inspection at the property, the crew on site — the where becomes proof, next to the when.
Without permission, the flow continues normally — and the system still triangulates an approximate location from the IP, recorded in the certificate alongside the other factors.
Audit trail
Every validation attempt is recorded with IP address, geolocation, device and method used — including the incorrect ones.
A wrong code before the right one also tells the story of the act. In a dispute, you demonstrate not only that the validation happened, but how it happened.
Configuration
Requirements are set per signer, per envelope. A purchase agreement can require a selfie and a sender password; a routine authorization, just the code by email.
Within the same envelope, each signer can have a different combination: more layers for whoever takes on the obligation, less friction for everyone else.
Yes. The 6-digit code is generated and sent on the spot, and it is valid for 5 minutes. After that it expires and the signer requests a new one — the short window prevents intercepted codes from being reused.
It depends on the plan. Email codes, a sender-defined password and a basic selfie are on every plan, including Free — and every envelope records geolocation and unique access links as evidence. The signer's own A1 digital certificate starts on Starter. The advanced selfie with liveness detection, identity-document capture and optional facial biometrics are on Business and Enterprise, along with SMS codes.
By default, a selfie is not identity matching. The advanced selfie (Business and Enterprise) runs a liveness check — tested against the ISO/IEC 30107-3 presentation-attack standard — that confirms a real person is signing, not a photo or a recorded video; on its own it does not identify you or match your face against any database. On those plans the sender can additionally require an identity document and enable optional facial biometrics, which compare the signing selfie to the photo on that document — and even then nothing is checked against external databases. The basic selfie available on every plan is simply a live photo attached to the certificate as evidence of the act.
Yes. The combination is configurable per signer, per envelope: you can require, for example, a selfie and a sender password from the same person on a critical contract. Every validated factor goes into the audit trail and the certificate of completion.
The incorrect attempt is recorded like the rest: IP address, geolocation, device and method used. The full history, hits and misses, is consolidated in the certificate of completion when the envelope ends.
Talk to the team
Our team helps you calibrate the factors for each document type: when a code by email is enough and when it pays to require an advanced selfie with liveness. Get answers about features, plans and implementation directly on WhatsApp.